Workspace ONE Intelligence and Zimperium Mobile Threat Detection Integration

Blogging has been a real treat. I especially enjoy seeing what posts  receive more pageviews, and what content really resonates with people. 

The trend, is your friend; posts covering Zimperium and Workspace ONE integration receive anywhere from 570% to over 900% more views than the rest. With that, let's give the people what they want.

This week Zimperium would announce support full support for Workspace ONE Intelligence. Workspace ONE Intelligence is an extension of the Workspace ONE UEM platform that provides new features and capabilities. Some of these capabilities include;

  1. Trust Network
  2. Automation
  3. Dashboards / Reports / Widgets
  4. Consumer Apps SDK
With this latest release of zConsole from Zimperium, we can now stream threat events to Workspace ONE Intelligence.  Currently, Intelligence is able to use threat events from Zimperium to create dashboards/reports/widgets, and automated workflows.
Source: VMware

In this blog post, we'll cover how to integrate Workspace ONE Intelligence and Zimperium Mobile Threat Detection. 
But, before we get to the technical stuff, let's get to the good stuff.....

Kalalau Lookout, Kauai
Workspace ONE Intelligence Setup

  1. Login to your Workspace ONE UEM console
  2. In the upper right hand corner, click the 9 dots, and then click 'Workspace ONE Intelligence'

  3. Click 'Launch'

  4. In the new window that opens, click 'Integrations'

  5. In the new page that appears, locate Zimperium, and click 'Set up'

  6. Enter your administrator email address (this can be any email address, providing your team can be reached at the address). Click 'Done'
  7. At the next page you are provided with the integration token, hostname, and port. Keep this information handy.

  8. Click 'Done'
Zimperium Mobile Threat Detection Integration
  1. Login to the Zimperium zConsole and click 'Manage'
  2. Click 'Integrations'

  3. Click 'Threat Reporting', followed by 'Add Integration'

  4. Click 'VMware Workspace ONE Intelligence'
  5. Paste in the values obtained from Workspace ONE Intelligence
  6. Click 'Next', and specify the appropriate event level to send over. I have selected 'Normal and Above'. Before proceeding, name the integration appropriately as well. Then click 'Finish'

    * Note - at the time of this writing, June 24th 10:22 PM EDT, Detailed Forensics cannot be selected.
  7. Your new 'Threat Reporting' destination is created.

Outside of the scope of this post is how to create threats. To validate the integration works; I will create some threats and show the threats exported count increase.... 

Threat Event Log in zConsole, post-device tampering...

Updated Workspace ONE Intelligence integration detailing 16 threats reported. The reason the number of threats reported to Amazon Kinesis is greater, is due to Kinesis being integrated since April 29th, 2020. 

Ryan Pringnitz


Popular posts from this blog

Delivering Managed Configurations (key/value pairs) to Android applications with Workspace ONE UEM profiles

Clean up duplicate identities and users from Workspace ONE using REST API's and PowerShell

How to use Square's OkHttp Java library to access Workspace ONE UEM API's