Skip to content

VMWare Carbon Black Integration Guide🔗

Add a Carbon Black integration to your Secureworks® Taegis™ XDR tenant.

Add Carbon Black Collector

Before you begin, you must already have Carbon Black set up. You need the following from your Carbon Black Dashboard:

  • The XDR environment for Carbon Black to select
  • Your Carbon Black Org Key
  • Your Carbon Black API ID
  • Your Carbon Black API Secret Key

For information on how to get and create these, see the VMware Carbon Black Cloud Endpoint Standard and Enterprise EDR Integration Guide.

Taegis IP Address Ranges🔗

If you have an existing firewall or API gateway IP allow list configured for this integration, or are planning to configure one, add the following XDR IP address ranges for your Taegis region.

Taegis Region IP Address Range
Charlie 216.9.204.0/24
Delta 216.9.204.0/24
Echo 216.9.205.0/24
Foxtrot 216.9.206.0/24
Golf 216.9.207.0/24
Hotel 208.89.40.0/24
India 208.89.42.0/24
Juliet 208.89.41.0/24
Kilo 208.89.43.0/24
Quebec 208.89.44.0/24

Note

These would be the only IP ranges required for XDR integrations. If you previously configured older IP addresses, we recommend removing them after 30 days.

To add a Carbon Black integration, do the following:

  1. From the Taegis Menu, select Integrations → Cloud APIs.

    Tip

    Make sure you’re in the tenant you want to add an integration to.

  2. The Cloud API Integrations page displays.

  3. Select Add an Integration from the top right-hand corner. The Add Cloud API Integrations page displays.
  4. From the Optimized tab, select VMware Carbon Black. The Set Up Carbon Black panel displays.
  5. Enter your Environment.
  6. Enter your Org Key.
  7. Enter your API ID and API Secret Key.
  8. Select Done. The integration completes. If successful, a green checkmark will display next to Carbon Black in the Cloud API Integrations table.

Regions

XDR’s EU1 Region can only accept data from Carbon Black’s EU regions.