USTA – Account Takeover Prevention (ATP) is a ServiceNow integration that enables Security Operations teams to automatically ingest compromised credential alerts from the PRODAFT USTA Threat Intelligence platform and convert them into actionable Security Incident records.
Account takeover attacks remain one of the most common entry points for cyber attackers. Threat intelligence providers such as PRODAFT continuously monitor underground forums, malware logs, and credential leak sources to identify compromised accounts. However, organizations often struggle to operationalize these alerts within their existing incident response workflows.
The USTA ATP application bridges this gap by integrating the USTA threat intelligence feed directly into the ServiceNow Security Incident Response module. The application periodically retrieves compromised account alerts through the USTA API and creates corresponding Security Incident records within ServiceNow. This enables security analysts to detect and respond to potential account takeover events without leaving the ServiceNow platform.
This plugin ingests compromised credential data related to customer's corporate domain.
Ingested data is visible in Security Incident tables.
Detailed information is available in addition to references to U.S.T.A. tickets
Initial Release
Zurich instance with Security Incident Response application installed.