---
title: "Cybereason collector"
canonical: "https://docs.devo.com/space/latest/623378461/Cybereason%20collector"
format: markdown
---
> Macro (toc)

## Overview

Cybereason offers an endpoint protection platform. It delivers antivirus software, endpoint detection and response with one agent, and a suite of managed services.

## Integration overview

The data is collected using a Devo Collector that can be run on the Devo Collector server or standalone in a Docker container. The data is sent and stored in the Devo platform in these tables:

- `edr.cybereason.api_malop`
- `edr.cybereason.api_malware`

Cybereason exposes REST API resources to extract data such as:

| **Resource type** | **Definition** | **Devo table** |
| --- | --- | --- |
| Malop API | Returns the list of MalOps.<br>A MalOp (malicious operation) gives a contextualized view of the full narrative of an attack, correlated across all impacted endpoints.<br>Endpoint: `https://<your server address>:<port>/rest/crimes/unified`<br>Learn more [here](https://api-doc.cybereason.com/en/latest/tutorials/retrieveMalopsPre20.1.html?highlight=rest%2Fcrimes#retrieve-all-malops). | `edr.cybereason.api_malop` |
| Malware API | Returns details on malware currently in your environment.<br>Malware is any software intentionally designed to disrupt a computer, server, client, or computer network, leak private information, gain unauthorized access to information or systems, deprive access to information, or unknowingly interfere with the user's computer security and privacy.<br>Endpoint: `https://<your server address>:<port>/rest/malware/query`<br>Learn more [here](https://api-doc.cybereason.com/en/latest/APIReference/MalwareAPI/queryMalwareTypes.html#query-malware-types). | `edr.cybereason.api_malware` |

### Information about the endpoints

- Log in with the API: [https://nest.cybereason.com/api-documentation/all-versions/authentication.html](https://nest.cybereason.com/api-documentation/all-versions/authentication.html)
- MalOp endpoint info: [https://nest.cybereason.com/documentation/api-documentation/all-versions/get-malops#getmalops](https://nest.cybereason.com/documentation/api-documentation/all-versions/get-malops#getmalops)
- Malware endpoint info: [https://nest.cybereason.com/documentation/api-documentation/all-versions/query-malware-types#querymalware](https://nest.cybereason.com/documentation/api-documentation/all-versions/query-malware-types#querymalware)

## Vendor configuration

To pull the logs from the Cybereason endpoint you need:

| **Parameter** | **Description** |
| --- | --- |
| Host | The service address of the Cybereason installation. |
| Port | The service port of the Cybereason installation. |
| Username | Your Cybereason service username. |
| Password | Your Cybereason service password. |

With this information, the Cybereason collector can be configured later.

## Run the collector

Once the data source is configured, you can either send us the required information if you want us to host and manage the collector for you (<u>Cloud collector</u>), or deploy and host the collector in your own machine using a Docker image (<u>On-premise collector</u>).

> Macro (rw-ui-tabs-macro)
> 
> > Macro (rw-tab)
> 
> The Collector Server is a managed platform that allows running sets of different collectors grouped by Devo domain destinations.
> 
> To run an instance of this data collector, the next steps must be followed:
> 
> 1. In the **Collector Server** **GUI**, access the **domain** where you want to create this instance, click **Add Collector,** search for “**Cybereason - Integrations Factory**”, then click on the result.
> 2. In the **Version** field, select the latest value.
> 3. In the **Collector Name** field, set the value you prefer (this name must be unique inside the same Collector Server domain).
> 4. In the **Parameters** section, establish the **Collector Parameters** as follows below:
> 
> > ℹ️ Please, replace the placeholders `<username>,` `<password>`, `<host>`, and `<port>` with the values obtained in previous sections of this document, except the `<short_unique_identifier>` that can have the value you choose.Collector services detail
> 
> ```
> {
>   "cybereason": {
>     "id": "<short_unique_identifier>",
>     "enabled": true,
>     "credentials": {
>       "username": "<username>",
>       "password": "<password>"
>     },
>     "endpoint": {
>       "host": "<host_value>",
>       "port": "<port_value>"
>     },
>     "services": {
>       "malop": {
>         "request_period_in_seconds": 300,
>         "tag": "edr.cybereason.api_malop",
>         "start_time": "<YYYY-mm-DDTHH:MM:SS.sssZ>"
>       },
>       "malware": {
>         "request_period_in_seconds": 300,
>         "tag": "edr.cybereason.api_malware"
>       }
>     }
>   }
> }
> ```
> 
> > ℹ️ The value chosen for the `id` field will be used internally for having independent persistence areas.
> 
> > Macro (rw-tab)
> 
> This data collector can be run in any machine that has the Docker service available because it should be executed as a docker container. The following sections explain how to prepare all the required setup for having the data collector running.
> 
> ### Structure
> 
> The following directory structure should be created for being used when running the collector:
> 
> ```
> <any_directory>
> └── devo-collectors/
>     └── <product_name>/
>         ├── certs/
>         │   ├── chain.crt
>         │   ├── <your_domain>.key
>         │   └── <your_domain>.crt
>         ├── state/
>         └── config/ 
>             └── config.yaml 
> ```
> 
> > ⚠️ Replace `<product_name>` with the proper value.
> 
> ### Devo credentials
> 
> In Devo, go to **Administration → Credentials → X.509 Certificates**, download the **Certificate**, **Private key** and **Chain CA** and save them in `<product_name>/certs/`. Learn more about security credentials in Devo [here](#).
> 
> ![image-20240514-100348.png](media://6c503ba0-2801-4da4-8fe1-9ac3fc6240f3)
> 
> > ⚠️ Replace `<product_name>` with the proper value.
> 
> ### Editing the config.yaml file
> 
> ```
> globals:
>   debug: false
>   id: not_used
>   name: cybereason
>   persistence:
>     type: filesystem
>     config:
>       directory_name: state
> 
> outputs:
>   console_1:
>     type: console
> 
> inputs:
>   cybereason:
>       id: <short_unique_id>
>       enabled: true
>       endpoint:
>         host: "<host.to.cybereason.ext>"
>         port: "<port>"
>       credentials:
>         username: "<username>"
>         password: "<password>"
>       services:
>         malop:
>           request_period_in_seconds: 300
>           tag: edr.cybereason.api_malop
>           start_time: 2021-10-29T00:00:00.000Z
>         malware:
>           request_period_in_seconds: 300
>           tag: edr.cybereason.api_malware
> ```
> 
> ### Download the Docker image
> 
> The collector should be deployed as a Docker container. Download the Docker image of the collector as a .tgz file by clicking the link in the following table:
> 
> | **Collector Docker image** | **SHA-256 hash** |
> | --- | --- |
> | [collector-cybereason_if-docker-image-1.7.0](https://drive.google.com/file/d/1tNhdCBMtXtf_RCjMJsbKFvszQoRVrcBH/view?usp=drive_link) | `915109191793cae8adadb361d5d99190bf1109436c23b1c7f0b779ec2fa99b0b` |
> 
> Use the following command to add the Docker image to the system:
> 
> ```
> gunzip -c <image_file>-<version>.tgz | docker load
> ```
> 
> > ⚠️ Once the Docker image is imported, it will show the real name of the Docker image (including version info). Replace `<image_file>` and `<version>` with a proper value.
> 
> The Docker image can be deployed on the following services:
> 
> #### Docker
> 
> Execute the following command on the root directory `<any_directory>/devo-collectors/<product_name>/`
> 
> ```
> docker run 
> --name collector-<product_name> 
> --volume $PWD/certs:/devo-collector/certs 
> --volume $PWD/config:/devo-collector/config 
> --volume $PWD/state:/devo-collector/state 
> --env CONFIG_FILE=config.yaml 
> --rm 
> --interactive 
> --tty 
> <image_name>:<version>
> ```
> 
> > ⚠️ Replace `<product_name>`, `<image_name>` and `<version>` with the proper values.
> 
> #### Docker Compose
> 
> The following Docker Compose file can be used to execute the Docker container. It must be created in the `<any_directory>/devo-collectors/<product_name>/` directory.
> 
> ```
> version: '3'
> services:
>   collector-<product_name>:
>     image: <image_name>:${IMAGE_VERSION:-latest}
>     container_name: collector-<product_name>
>     volumes:
>       - ./certs:/devo-collector/certs
>       - ./config:/devo-collector/config
>       - ./credentials:/devo-collector/credentials
>       - ./state:/devo-collector/state
>     environment:
>       - CONFIG_FILE=${CONFIG_FILE:-config.yaml}
> ```
> 
> To run the container using docker-compose, execute the following command from the `<any_directory>/devo-collectors/<product_name>/` directory:
> 
> ```
> IMAGE_VERSION=<version> docker-compose up -d
> ```
> 
> > ⚠️ Replace `<product_name>`, `<image_name>` and `<version>` with the proper values.

| **Release** | **Released on** | **Release type** | **Details** | **Recommendations** |
| --- | --- | --- | --- | --- |
| `v1.7.0` | 7/15/2024 | [IMPROVEMENT] | **Improvements:**<br>- The DevoCollectorSDK Python package (devo-collector-sdk) has been updated from "1.16.2" to "1.16.3"<br>### Bug Fix:<br>- Fixed a bug related to the start time for a service. | `Recommended version` |
| `v1.6.0` | 6/3/2024 | [IMPROVEMENT] | **Improvements:**<br>- The DCSDK Docker base image has been updated from "1.5.0" to "1.5.1"
- The DevoCollectorSDK Python package (devo-collector-sdk) has been updated from "1.16.1" to "1.16.2" | `Update` |
| `v1.5.0` | 5/20/2024 | [IMPROVEMENT] | **Improvements:**<br>- Updated Docker base image from version "1.2.0" to "1.5.0"
- Updated DCSDK from version "1.11.1" to "1.16.1" | `Update` |
| `v1.4.0` | 5/9/2024 | [IMPROVEMENT] | **Improvements:**<br>- Upgrade DC SDK to the latest version 1.11.1
- Upgrade the Docker base image to 1.2.0 | `Update` |
| `v1.3.0` | 1/24/2024 | [IMPROVEMENT] | **Improvements:**<br>- Upgraded DCSDK from 1.9.1 to 1.10.2 | `Update` |