Prerequisites
- A Darktrace appliance with access to the Threat Visualizer
- Network connectivity from Darktrace to
https://api.wirespeed.co
Setup in Wirespeed
- Login to Wirespeed
- Navigate to Integrations > Add Integration > Darktrace
- Select Webhook Details
- Copy the Webhook URL and Webhook Secret — you’ll need these for the Darktrace configuration
Setup in Darktrace
- Login to Darktrace Threat Visualizer
- Navigate to Modules
- Select HTTPS
- Click Workflow Integrations
- Enable the integration and select the devices or subnets you want to monitor
Configure HTTP/HTTPS Alerts
- In the Configuration for HTTP/HTTPS Alerts section, click New to create a new alert configuration
- Toggle Send Alerts to enabled
- In the URL field, paste the Webhook URL from Wirespeed
- Toggle Show Advanced Options to expand authentication settings
- Set Authentication to Basic
- Enter
wirespeedas the Username - Enter the Webhook Secret from Wirespeed as the Password
- Click Verify alert settings to test the connection
- Save your configuration
What Gets Ingested
Wirespeed receives and processes the following from Darktrace:- Cyber AI Analyst Incidents — AI-generated investigation summaries
- Model Breaches — Behavioral detections from Darktrace’s unsupervised ML models
Troubleshooting
Webhook verification fails
Webhook verification fails
Ensure your Darktrace appliance can reach
https://api.wirespeed.co on port 443. Check firewall rules and proxy settings.No detections appearing
No detections appearing
Verify that Send Alerts is enabled and that the devices you want to monitor are selected in the Workflow Integrations panel.
Authentication errors
Authentication errors
Double-check that Basic authentication is selected, the username is exactly
wirespeed, and the password matches your Webhook Secret from Wirespeed.
