Skip to technology filters Skip to main content
Dynatrace Hub

Extend the platform,
empower your team.

Popular searches:
Home hero bg
Security EnrichmentSecurity Enrichment
Security Enrichment

Security Enrichment

Connect any HTTP-based threat intelligence source to enrich observables.

App
Free trialDocumentation
Flow diagram.Security Enrichment Overview
  • Product information
  • Release notes

Overview

Dynatrace Security Enrichment enables you to integrate threat intelligence services — commercial, open-source, or proprietary — to enrich security observables such as IP addresses with reputation, geolocation, and contextual data.

Security Enrichment provides a unified management interface to define HTTP-based enrichment connections, configure vendor-specific options, map responses to a normalized schema, and share connections across your team.

Key capabilities
  • Custom connections: Define HTTP request templates (method, URL, headers, query parameters, body) to call any REST-based threat intelligence API. Use placeholder variables such as {{observable.value}} and {{authentication.secret}} for dynamic request composition.
  • Vendor blueprints: Get started faster with pre-configured templates for popular providers such as AbuseIPDB and VirusTotal. Blueprints prefill the connection wizard with recommended defaults — just add your API key.
  • Response mapping: Transform raw vendor JSON responses into Dynatrace's normalized enrichment report schema (mappedResponse) using DQL-based mapping. This ensures consistency of enrichment results across vendors and prepares the data for downstream use.
  • Caching: Reduce latency and external API quota consumption through caching of enrichment results.
  • Workflow action: Use the included workflow action in Workflows to enrich observables in automated triage, response and remediation playbooks.
  • Custom options: Configure vendor-specific parameters (for example, maxAgeInDays or verbose for AbuseIPDB). These are validated and applied at execution time.

Use cases

Security Enrichment–powered contextualization of observables enables:

  • Threat-informed security investigations: Enrich IP addresses with reputation data, geolocation, abuse reports, and additional context to detect anomalous and malicious activity in Investigations.
  • Automated threat-alert triaging: Classify and prioritize security alerts using enriched threat intelligence in Workflows. Build automated SOAR playbooks that branch on reputation scores, escalate malicious findings, and suppress known-benign noise.
  • Enhanced threat detection findings: Add external enrichment data to IP addresses in Threats & Exploits for faster, more accurate decision-making.
  • Bring your own enrichment: Connect proprietary intelligence feeds, such as MISP or internal services, that are not natively supported to operationalize your existing threat intelligence feeds and internal data sources inside Dynatrace.

Are you looking for additional use cases and functionality? Let us know in the Dynatrace Community Forum!

Get started

For setup and configuration instructions, see Security Enrichments.

Details

Vendor blueprints

Blueprints are Dynatrace-governed, read-only templates shipped with the app. They prefill the connection wizard with tested configurations for specific vendors. Blueprint updates are delivered through new app versions and apply only to newly created connections — existing connections are not modified.

Currently available blueprints:

  • AbuseIPDB — IP reputation checks using the AbuseIPDB Check endpoint.
  • VirusTotal — IP address reports from the VirusTotal API.
Migration

Users of the standalone AbuseIPDB or VirusTotal apps can migrate to the built-in blueprint connection. See migration guide

Outbound connectivity

Custom enrichment connections call external endpoints from the Dynatrace platform. Depending on your network setup, you may need to allowlist the outbound domains used by your enrichment connections.

Dynatrace
DocumentationMore Information
By Dynatrace
Dynatrace support center
Subscribe to new releases
Copy to clipboard

Full version history

ReleaseDate

Full version history

1.4.1

Fixes and maintenance

  • Fix discard modal in intent mode
  • Improve connection create stepper

Full version history

1.3.1

Feature updates

  • Split the code editor for query parameters and headers into key-value input-fields
  • Allow empty header and query parameter values

Full version history

1.2.0

Feature updates

  • Add workflows template section to connection overview

Fixes and maintenance

  • Update to strato v3

Full version history

1.1.0

  • Initial release
Dynatrace Hub
Hub HomeGet data into DynatraceBuild your own app
Dynatrace Intelligence - Agentic Operations SystemThe Dynatrace Agentic AI ecosystem
All (914)Log Management and AnalyticsKubernetesAI and LLM ObservabilityInfrastructure ObservabilitySoftware DeliveryApplication ObservabilityBusiness ObservabilityDigital Experience
Filter
Type
Built and maintained by
Deployment model
SaaS
  • SaaS
  • Managed
Partner FinderBecome a partnerDynatrace Developer

Application Security

Scale your DevSecOps with our unique approach to securing clould-native applications at runtime combined with intelligent automation.

Get started with these essentials

Vulnerabilities logo

Vulnerabilities

Detect and prioritize vulnerabilities to improve your environment's security.

Security Posture Management logo

Security Posture Management

Detect, prioritize, and remediate security and compliance findings with SPM.

Threats & Exploits logo

Threats & Exploits

Understand, triage, and investigate detection findings and alerts.

Investigations logo

Investigations

Fast and precise incident response on Grail data with DQL queries.

Real-time vulnerability detection at runtime

Get continuous monitoring of third-party, code-level & runtime vulnerabilities.

Vulnerabilities logo

Vulnerabilities

Detect and prioritize vulnerabilities to improve your environment's security.

Continuous Security Posture Management

Simplify compliance monitoring with pre-built policies for CIS, DORA, DISA STIG, and more, saving time and reducing complexity.

Security Posture Management logo

Security Posture Management

Detect, prioritize, and remediate security and compliance findings with SPM.

Protect your environment right when attacks happen

Detect and block the most severe attacks without affecting critical processes.

Threats & Exploits logo

Threats & Exploits

Understand, triage, and investigate detection findings and alerts.

Detect, investigate and respond to threats

Investigate and respond to cloud security incidents with powerful analysis tools

Investigations logo

Investigations

Fast and precise incident response on Grail data with DQL queries.

Threat intelligence ingest & enrichment

Ingest threat reports and enrich observables with threat intelligence integrations.

Security Enrichment logo

Security Enrichment

Connect any HTTP-based threat intelligence source to enrich observables.

AbuseIPDB logo

AbuseIPDB

Enrich observables with threat intelligence from AbuseIPDB.

VirusTotal logo

VirusTotal

Enrich observables with threat intelligence from VirusTotal.

CrowdStrike logo

CrowdStrike

Ingest CrowdStrike detection findings, threat reports, and audit logs.

LevelBlue (AlienVault) OTX logo

LevelBlue (AlienVault) OTX

Ingest LevelBlue (AlienVault) OTX threat reports.

Security findings ingest

Ingest detection, vulnerability, and compliance findings, as well as security scan events, and audit logs from DevSecOps product integrations.

See more (17)
OCSF logo

OCSF

Ingest security findings in Open Cybersecurity Schema Framework (OCSF) format.

Amazon ECR logo

Amazon ECR

Ingest Amazon Elastic Container Registry vulnerability findings and scan events.

Google Artifact Registry logo

Google Artifact Registry

Ingest Google Artifact Registry vulnerability findings.

AWS Security Hub logo

AWS Security Hub

Ingest AWS Security Hub vulnerabilities, detections, and compliance findings.

Microsoft Defender for Cloud logo

Microsoft Defender for Cloud

Ingest Microsoft Defender for Cloud security findings and scan events.

Tenable logo

Tenable

Ingest Tenable vulnerability findings, scan events, and audit logs.

Security logs ingest

Ingest logs from security-related products.

See more (2)
Akamai logo

Akamai

Ingest logs and security events from Akamai products.

CyberArk logo

CyberArk

Ingest CyberArk audit logs via SIEM integration for reporting and analysis.

Okta logo

Okta

Ingest Okta audit logs via the System logs API.

AWS Web Application Firewall (WAF) logo

AWS Web Application Firewall (WAF)

Web application firewall that lets you monitor the HTTP(S) requests.

Azure logs logo

Azure logs

Get insights from Azure logs with Log Management and Analytics.

Amazon API Gateway logo

Amazon API Gateway

Service for developers to create, publish, maintain, monitor, and secure APIs.

More resources

GitHub Copilot Coding Agent logo

GitHub Copilot Coding Agent

Automate vulnerability remediation and boost developer productivity.

GitHub Copilot Custom Agent logo

GitHub Copilot Custom Agent

Automate your development workflows with specialized agent definitions.

Are you looking for something different?

We have hundreds of apps, extensions, and other technologies to customize your environment

Extend your knowledge

Learn the Dynatrace Query Language

Learn the Dynatrace Query Language

Explore data, discover patterns, anomalies and outliers, and create statistical modeling with DQL, our powerful query language.
Learn DQL
Solve security issues with custom apps

Solve security issues with custom apps

Dynatrace Developer makes it easy to create custom apps for your organization. Start with one of our templates or use your own code.
Build apps
Skill up with on-demand courses

Skill up with on-demand courses

Go to Dynatrace University for focused courses and learning paths -- from platform basics to key certifications.
Build skills