Let Oomnitza be your single source of truth!
You'll get visibility of data breaches as data from Have I Been Pwned? is automatically transformed into consumable information and actionable insights.
Connect Oomnitza and Have I Been Pwned? in minutes
Create configurable workflows that fetch detailed information about account and system (domain) breaches including the source and time of the breach, and the nature of the data compromised.
Navigation
Before you start
Before you can create the integration with Oomnitza, you need to have added your credentials to Oomnitza.
Note
These workflows use version 3 of the Have I been Pwned? API which requires the purchase of a rate-limited API key.
Creating workflows
Create user workflows
To create a user workflow, you must complete these steps:
- Click Configuration > Workflows
- Click Add (+).
- Use search to find and select the Users object.
- Edit the Begin Block and add rules to trigger the workflow. For example, if you set the Actions to Schedule and add a rule so that the Email Equals <EmployeeEmail> you can trigger a workflow to fetch a user matching a certain name on a specific date. Refer to Using the Begin block.
- Drag and drop the API block onto the Sandbox.
- Click Edit on the API block and enter Have I Been Pwned? in the search field.
- Select a preset from the list below. To choose a preset, click the forward arrow (>).
- Select the credentials that you created in Adding your Have I Been Pwned? credentials to Oomnitza.
- Select Advanced Mode.
-
Select the Response tab. Map the response by placing
{{response}}in the Response field and mapping it to a custom long text Oomnitza field, such as API Response. - Connect the Blocks.
- Save, validate, and activate your workflow.
Using the Get Breaches filtered by domain preset
The Get Breaches filtered by domain preset filters the result set to only breaches against the domain specified. It is possible that one site (and consequently domain), is compromised on multiple occasions.
Each request to the API must be accompanied by the name of the app consuming the service.
For further information, see Have I Been Pwned? Getting all breached sites in the system
Using the Get Breaches for an Account preset
The Get Breaches for an Account preset return a list of all breaches a particular account (email address) has been involved in.
Note
By default, only the name of the breach is returned rather than the complete breach data
For further information, see Getting all breaches for an account
Comments
0 comments
Please sign in to leave a comment.