Integrating with OpenDNS Umbrella

If your organization uses OpenDNS for DNS services, you can integrate a domain feed from ThreatStream to OpenDNS. The domain feed updates every four hours to ensure your OpenDNS uses the latest threat intelligence.

When integrated, the top 10,000 domains from ThreatStream populate a Custom Integration List set up on OpenDNS based on a search filter that you specify in ThreatStream.

There are two steps to setting up the integration:

  1. Generate an OpenDNS Customer Key.
  2. Activate the integration within ThreatStream.

To generate an OpenDNS Umbrella Customer Key:

  1. Login to OpenDNS.
  2. Click Policies and navigate to Policy Components > Integrations.

  3. Click Add.
  4. Enter a name for the integration. Example: ThreatStream Domains.
  5. Check Enable.
  6. Copy the Customer Key from the URL. Customer Keys are located after customerKey= in the URL.

    Make sure you only copy the Customer Key and not the entire URL.
  7. Click Save.

To integrate ThreatStream with OpenDNS:

  1. Log in to the ThreatStream portal.

  2. In the bottom-left corner of the side navigation panel, click > ThreatStream and then click Integrations.

  3. Click Activate in the OpenDNS Umbrella box.
  4. Paste or enter your OpenDNS Customer Key.

    Make sure you enter only the Customer Key and not the entire URL that contains the key.
  5. Enter a Filter Query. For more on constructing a search query, see Constructing Advanced Observable Search Filters.

    For example: (status="active") AND (type=domain) AND (confidence>=85) AND (modified_ts>=90d) AND (severity!=low) AND (severity!=medium)

    Note: As a best practice, test your filter on the Advanced Search screen. Note that only the top 10,000 domains returned for the filter will be sent to OpenDNS.

    Regardless of the filter you enter, only domain observables with active status will be sent to OpenDNS. The filter you specify can be used to restrict the observables sent to OpenDNS to a more specific subset.

  6. Click Save.

    The status button for the service changes to Deactivate. The service is activated.

To verify that your OpenDNS integration is active:

  1. Login to OpenDNS.
  2. Click Configuration and navigate to System Settings > Integrations.
  3. Expand the ThreatStream integration.
  4. Click See Domains.
  5. Verify that the list of domains is populated.