This article shows how to leverage the Lumu Defender API and Check Point Harmony Security API to mitigate security risks.
1. Open your Web browser and access the Check Point Infinity Portal. Log in into the portal if you are not already logged in.2. On the top navigation bar, click the Gear icon on the right side of the screen. Then, click on API Keys.3. On the API Keys window, click on New at the top of the page. Then click New account API key.4. Fill the required information within the CREATE A NEW ACCOUNT API KEY modal as follows:a. Under Service (1), search for and select the Email & Collaboration option. You can type in the field to narrow down the options shown.b. Set an Expiration (2) date and time by clicking on the calendar and the scroll buttons. Choose an expiration date based on your internal security policy guidelines.c. Under Description (3), type a distinctive description to identify the API keyd. When done, click on the blue Create (4) button.e. A new window will appear, containing the Client ID (5), Secret Key (6), and Authentication URL (7). Make sure you store this information safely. Once you do, click Close (8).
This will be the only time you will be able to record it. If you lose this info, you will need to do the entire process from the beginning.
To collect the Lumu Defender API key, please refer to the Defender API document.
To collect your Lumu company UUID, log in to your Lumu portal. Once you are in the main window, copy the string below your company name.
For Windows users, follow the Install Docker Desktop for Windows documentation to install the Docker Engine.
#!/usr/bin/env bash
RED='\033[0;31m'
GREEN='\033[0;32m'
CYAN='\033[0;36m'
YELLOW='\033[1;33m'
BOLD='\033[1m'
RESET='\033[0m'
info() { echo -e "${CYAN}[INFO]${RESET} $*"; }
success() { echo -e "${GREEN}[OK]${RESET} $*"; }
warn() { echo -e "${YELLOW}[WARN]${RESET} $*"; }
error() { echo -e "${RED}[ERROR]${RESET} $*" >&2; }
prompt() { echo -e "${BOLD}${YELLOW}$*${RESET}"; }
IMG=lumutools/harmony-email-threat-feeder:latest
INTEGRATION_NAME=harmony-email-threat-feeder
INTEGRATION_NAME_IOC=harmony-email-threat-feeder-ioc
INTEGRATION_DIR=${HOME}/HarmonyEmailResponse
VOLUME_DATA=${INTEGRATION_DIR}/data:/app/data
VOLUME_CONFIG=${INTEGRATION_DIR}/data/.config.toml:/app/.config.toml:ro
VOLUME_IOC=${INTEGRATION_DIR}/data/ioc.db:/app/data/ioc.db:ro
mkdir -p "${INTEGRATION_DIR}/data"
chmod -R o+w "${INTEGRATION_DIR}/data" > /dev/null 2>&1
run_config() {
info "Running configuration script ..."
if docker run --rm -it -v "${INTEGRATION_DIR}/data:/app/data" "${IMG}" bash run_config; then
success "Configuration completed."
else
error "Configuration script failed."; return 1
fi
}
start_integration() {
info "Setting up IOC integration '${INTEGRATION_NAME_IOC}' ..."
if [[ ! -f "${INTEGRATION_DIR}/data/.config.toml" ]]; then
error "Please configure the integration first."; return 1
fi
if ! docker container inspect "${INTEGRATION_NAME_IOC}" &>/dev/null; then
info "Integration '${INTEGRATION_NAME_IOC}' does not exist. Creating it ..."
if ! docker create \
-v "${VOLUME_DATA}" \
-v "${VOLUME_CONFIG}" \
--restart unless-stopped \
--log-driver json-file \
--log-opt max-size=30m \
--log-opt max-file=3 \
--name "${INTEGRATION_NAME_IOC}" \
"${IMG}" bash run_ioc; then
error "Failed to create IOC integration."
return 1
fi
else
warn "Integration '${INTEGRATION_NAME_IOC}' already exists. Skipping its creation."
fi
if docker start "${INTEGRATION_NAME_IOC}"; then
success "IOC integration started."; sleep 5
else
error "Failed to start IOC integration."; return 1
fi
info "Setting up main integration '${INTEGRATION_NAME}' ..."
if ! docker container inspect "${INTEGRATION_NAME}" &>/dev/null; then
info "Integration '${INTEGRATION_NAME}' does not exist. Creating ..."
if ! docker create \
-v "${VOLUME_DATA}" \
-v "${VOLUME_CONFIG}" \
-v "${VOLUME_IOC}" \
--restart unless-stopped \
--log-driver json-file \
--log-opt max-size=30m \
--log-opt max-file=3 \
--name "${INTEGRATION_NAME}" \
"${IMG}" bash run_component; then
error "Failed to create main integration."; return 1
fi
else
warn "Integration '${INTEGRATION_NAME}' already exists. Skipping create."
fi
if docker start "${INTEGRATION_NAME}"; then
success "Main integration started."
else
error "Failed to start main integration."; return 1
fi
}
check_status() {
info "Checking status of integrations ..."
if [[ ! -f "${INTEGRATION_DIR}/data/.status.ndjson" ]]; then
error "Status check failed. Verify if your integration has been deployed."; return 1
fi
if docker run --rm -it -v "${VOLUME_DATA}":ro "${IMG}" bash run_status; then
success "Status check completed."
else
error "Status check failed."; return 1
fi
}
show_logs() {
echo ""
prompt "Select which logs to view:"
echo -e " ${CYAN}1${RESET}) IOC integration (${INTEGRATION_NAME_IOC})"
echo -e " ${CYAN}2${RESET}) Main integration (${INTEGRATION_NAME})"
echo ""
read -rp "$(prompt 'Enter option [1/2]: ')" choice
case "${choice}" in
1)
info "Showing logs for '${INTEGRATION_NAME_IOC}' ..."
docker logs --tail 100 -f "${INTEGRATION_NAME_IOC}"
;;
2)
info "Showing logs for '${INTEGRATION_NAME}' ..."
docker logs --tail 100 -f "${INTEGRATION_NAME}"
;;
*)
error "Invalid option '${choice}'."
return 1
;;
esac
}
usage() {
echo ""
prompt " HARMONY EMAIL SECURITY RESPONSE INTEGRATION MANAGEMENT"
echo -e " ${BOLD}Usage:${RESET} $0 "
echo ""
echo -e " ${CYAN}config${RESET} Run configuration"
echo -e " ${CYAN}start${RESET} Start integration"
echo -e " ${CYAN}status${RESET} Check integration status"
echo -e " ${CYAN}logs${RESET} Show integration logs"
echo ""
}
case "${1}" in
config) run_config ;;
start) start_integration ;;
status) check_status ;;
logs) show_logs ;;
*) usage
[[ -n "${1}" ]] && error "Unknown command '${1}'."
exit 1 ;;
esac
You must fill in the configuration data carefully. If there are any mistakes or missing data, you’ll receive errors during the deployment and runtime of the integration.
We strongly recommend correcting any credential errors before attempting to start the integration using the start command.
If you have run this process before, you may receive warning messages about the existence of components. To ensure you have the latest version of the integration, we recommend removing the existing integration containers before entering the start command.
We kindly request you to, when issuing a support case, attach the integration logs collected using the steps described in this section.
1. IOC integration: This component keeps an up-to-date record of IOCs from Lumu detections. Here, you can check Lumu API-related errors.
2. The main integration: This component manages the IOCs’ lifecycle in the third-party platform based on the data curated by the first component. Here, you can check any third-party API error raised during the IOC management tasks.
All the uploaded IOCs can be found in the Anti-Phishing Block-List module under the Harmony Email & Collaboration configuration. You can get here by clicking on Security Settings on the left-hand menu and clicking on the Exceptions header. The list is under the Anti-Phishing option.
Ensure you select the Block-List option next to the Anti-Phishing Exceptions title. You will see the list of the exception managed by the integration.