Automatically sync Cyren Malware URL threat intelligence into SentinelOne via AWS Lambda. No manual imports, no custom code. Deploys in under 5 minutes.
The Cyren Malware URL Threat Intelligence Connector for SentinelOne automates the ingestion of Cyren's malware URL threat intelligence feed directly into your SentinelOne Singularity platform. Deployed as a serverless AWS Lambda function triggered by Amazon EventBridge, this connector continuously polls the Cyren CCF Malware URL feed and pushes malicious URL indicators of compromise (IOCs) to SentinelOne's Threat Intelligence API, keeping your security platform current automatically. How It Works: 1. Amazon EventBridge triggers the Lambda function every 6 hours 2. Lambda authenticates with the Cyren CCF API using your JWT token 3. Malware URL indicators are fetched with full PersistentToken pagination 4. Each IOC is pushed to SentinelOne's /web/api/v2.1/threat-intelligence/iocs endpoint 5. All operations are logged to Amazon CloudWatch. What You Get: - Fully automated malware URL IOC sync from Cyren to SentinelOne every 6 hours - Persistent pagination via DynamoDB - AWS Secrets Manager for credentials - CloudFormation one-click deployment - Full CloudWatch audit logging - 100% serverless. About Data443: Data443 Risk Mitigation, Inc. is a leading provider of data security and threat intelligence solutions.
This product extends the functionality of SentinelOne and without it, this product has very limited utility. Please note that SentinelOne might require its own license for full functionality with this listing.
Highlights
Automated sync of Cyren Malware URL IOCs into SentinelOne every 6 hours - zero manual effort required
Serverless AWS Lambda + CloudFormation deployment - fully operational in under 5 minutes
Secure credential storage via AWS Secrets Manager with full CloudWatch audit logging on every sync
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
This listing offers one pricing dimension: the Basic subscription tier, billed as a contract by unit quantity. You commit to a set number of units for the contract term, and your cost scales with the number of units you select. There are no separate size tiers or usage add-ons to choose between. The connector feeds real-time threat data — malicious IPs, phishing URLs, and malware domains — into your endpoint protection for automated blocking. Because only one tier is available, pricing depends solely on how many units you purchase.
Top-of-mind questions for buyers
What counts as one unit under the Basic subscription tier for billing?
The listing bills by unit quantity under a single Basic tier, but the marketplace data does not define what one unit represents. Reach out to the vendor to confirm whether a unit maps to a protected endpoint, a feed, a user, or another measure before you commit.
What threat data does the Basic subscription push into my endpoint protection?
The connector detects malicious IP addresses, phishing URLs, and malware domains across a global network. It converts high-risk indicators automatically and pushes them to your endpoint protection for blocking. By default, only high-confidence threats with a risk score of 80 or higher trigger a push.
Does this replace my existing endpoint threat intelligence, or add to it?
It supplements your existing feeds rather than replacing them. The connector adds a layer of real-time threat data your current feeds may not cover. Your endpoint tool deduplicates indicators automatically, so you avoid duplicate blocking or repeated alerts when both sources flag the same threat.
data443.com
Helpful?
Vendor refund policy
All sales are final. No refunds are provided for annual contracts after the 48-hour cancellation window. If you cancel within 48 hours of purchase, AWS automatically issues a full refund. For billing issues or disputes, contact support@data443.com and we will review your case within 5 business days. Refunds are at the sole discretion of Data443 Risk Mitigation, Inc.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Automatically sync Cyren IP Reputation threat intelligence into SentinelOne via AWS Lambda. No manual imports, no custom code. Live in under 5 minutes.
Automatically sync Cyren IP Reputation threat intelligence into CrowdStrike Falcon as custom IOCs via AWS Lambda. Real-time threat detection without manual imports.
Automatically sync Cyren Malware URL threat intelligence into CrowdStrike Falcon as custom IOCs via AWS Lambda. Serverless, secure, deploys in under 5 minutes.
Automatically ingest Cyren IP Reputation threat intelligence into AWS Security Hub as findings via AWS Lambda. Unified security visibility without manual imports.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.