Security Incident Response Integration with Zscaler
Performs a reputation look up of observables in Security incident against the global threat library maintained by Zscaler.
Install Trend
View Install Data
| Date | Install Count | Change |
|---|---|---|
| 2026-09-09 | 0 | - |
| 134 days of no change | ||
| 2026-04-27 | 43 | -43 |
| 186 days of no change | ||
| 2025-10-22 | 42 | +1 |
| 7 days of no change | ||
| 2025-10-14 | 41 | +1 |
| 68 days of no change | ||
| 2025-08-06 | 40 | +1 |
| 7 days of no change | ||
| 2025-07-29 | 39 | +1 |
| 6 days of no change | ||
| 2025-07-22 | 38 | +1 |
| 70 days of no change | ||
| 2025-05-12 | 37 | +1 |
| 31 days of no change | ||
| 2025-04-10 | 36 | +1 |
| 2 days of no change | ||
| 2025-04-07 | 35 | +1 |
| 15 days of no change | ||
| 2025-03-22 | 34 | +1 |
| 16 days of no change | ||
| 2025-03-05 | 33 | +1 |
| 29 days of no change | ||
| 2025-02-03 | 32 | +1 |
| 7 days of no change | ||
| 2025-01-26 | 31 | +1 |
| 87 days of no change | ||
| 2024-10-30 | 28 | +3 |
About
The Security Incident Response integration with Zscaler enables Security Analysts to do the following:
- Perform a reputation lookup of observables against the global threat library maintained by Zscaler.
- Add or remove observables from the block list or allow list on Zscaler.
- Retrieve and review sandbox reports from Zscaler for an MD5 hash.
In addition, this integration also supports creating a security incident from Patient 0 alerts that are generated in Zscaler when a user downloads an unknown malicious file.
Key Features
- Threat Lookup:
- Analyst will be able to trigger reputation lookups on URL/IP/Domain.
- Deny/Allow URLs/IPs/Domain:
- Analyst will be able to add URLs/IPs/Domain to tenant-specific DenyList/AllowList or other URL categories.
- Supports periodic removal of entries from the list based on expiration value.
- Supports an Approval workflow.
- Sandbox Report Lookup:
- Analyst will be able to look up the Sandbox report of the MD5 hash and store it against the incident.
- Create Security Incidents out of Patient 0 alerts:
- Support for ingestion of patient 0 alerts and create security incidents out of them.