ThreatQuotient ThreatQ
Introduction
This guide tells you how to authenticate the ThreatQuotient ThreatQ connector in Swimlane using OAuth 2.0 Password Grant authentication.
You will enable API access in ThreatQ, collect the required credentials, and configure the connector in Swimlane.
Prerequisites
ThreatQ Access Requirements
You must have access to a ThreatQuotient ThreatQ account with permissions to:
- Access the ThreatQ API
- Authenticate using OAuth (username/password-based grant)
- Create, read, update, and delete indicators, events, and import sessions
- View API version information (standard or beta)
Permissions are managed through ThreatQ roles. Ensure the API user has sufficient privileges for the actions you intend to automate.
Required Credentials
During setup, you will collect the following:
- API Base URL
- API User Email
- Client Password
- OAuth Client ID
- API Type (standard or beta)
API Types
ThreatQ supports different API types depending on your deployment.
API Type | Description |
|---|---|
standard | Default ThreatQ production API |
beta | Beta or preview API features (if enabled in your environment) |
Ensure the API type selected in Swimlane matches your ThreatQ instance.
ThreatQ Setup
Take the following steps to prepare ThreatQ for API authentication:
- Log in to the ThreatQ platform.
- Confirm API access is enabled for your user account.
- Identify the correct API base URL for your ThreatQ instance.
- Confirm the OAuth Client ID assigned to your environment.
- Verify whether your instance uses the standard or beta API.
ThreatQ uses OAuth password grant authentication, which requires a valid API user email and password.
Scopes and Permissions
ThreatQuotient does not require explicit OAuth scopes to be defined during authentication. Access control is enforced through ThreatQ roles and permissions assigned to the API user.
Ensure the API user has permissions for the following functional areas as needed:
- Indicators (read, search, create, update)
- Events (create, list, import)
- Imports and import sessions
- Queries and searches
For more information on ThreatQ roles and permissions, refer to the ThreatQuotient documentation.
Connector Configuration in Swimlane
Take the following steps to configure the ThreatQuotient ThreatQ connector asset in Swimlane:
- Log in to Turbine.
- From the left-hand navigation pane, click ORCHESTRATION, then click Assets.
- Click the plus (+) icon to open the Configure your Connector Asset window.
- Select ThreatQuotient ThreatQ from the Asset type list.
- Fill in the Asset Settings and Asset Input as shown below.
Configuration Parameters - OAuth Password Grant
Field | Description | Required/Optional |
|---|---|---|
url | ThreatQ API base URL | Required |
API user email address | Required | |
password | API user password | Required |
clientId | OAuth Client ID from ThreatQ | Required |
api_type | API type (standard or beta) | Required |
verify_ssl | Enable/Disable SSL certificate verification | Optional |
http_proxy | Optional proxy configuration | Optional |
Troubleshooting
If authentication fails:
- Verify the API base URL is correct.
- Confirm the API user email and password are valid.
- Ensure the correct OAuth Client ID is used.
- Verify the selected API type matches your ThreatQ deployment.
- Check SSL and proxy configuration settings.
Result
You have successfully authenticated the ThreatQuotient ThreatQ connector in Swimlane and can now automate threat intelligence ingestion and management workflows.
Sources
- Swimlane ThreatQuotient ThreatQ Connector Documentation https://docs.swimlane.com/connectors/threatquotient-threatqο»Ώ