Navigate to the Policy → <Admin Domain Name> → Threat Intelligence → Feed Configuration page and perform the following tasks -
Create a threat feed using file import
In the Feed Configuration page, Click the
icon.The Configure Feed tab is displayed by default.
.jpg)
Configure the following fields:
Name: Specify the name of the threat feed
Publisher Name: Specify the name of the publisher.
Visibility: Select the required domain from the drop-down list.
Feed Source: Select File Import for manual upload of threat feed or select TAXII Server to automate uploading threat feed from TAXII server.
Note
File Import is selected by default.
Import File: Click Browse, and upload the STIX-formatted JSON file containing your IoC. No other filetype is supported.
IoC Types to Import: This list is populated based on the IoC types in the uploaded JSON file. When creating a feed, all IoC types are enabled by default. You can deselect any IoC types you do not want to import.
When the fields are configured, click the Save button.
An information message is displayed on saving the threat feed successfully.
Create an automated threat feed using TAXII server
In the Feed Source, select TAXII Server.
Note
The system allows a maximum of 5 TAXII server configurations to be enabled at any given time.
TAXII server configurations settings are displayed.
Configure the following fields:
Enable: Select Yes to enable and No to disable the TAXII server.
Server Discovery URL: Specify the URL of server.
Server Authentication: Select the required authentication from the drop-down list and provide User Name and Password.
API Roots: Click Add and API Root Configuration is displayed.
Configure the following fields:
API Root URL: Specify the API root URL.
Use Discover URL Credentials: This field is selected by default. You can deselect it and provide the username and password.
Collection ID: Specify the collection ID and click Add to add the collection ID to the Collection list.
Click Save.
.png)
Note
To delete API root entry, select the specify entry and click Delete.
IoC Types to Import: This list is populated based on the IoC types. When creating a feed, all IoC types are enabled by default. You can deselect any IoC types you do not want to import.
Note
Each configured TAXII server is limited to a maximum of 10 collection IDs.
Click Test Connection to test the connection with the TAXII server and the API root URLs.
Note
An information message is displayed on successfully testing the connection. If the connection is unsuccessfully, check the settings again.
When the fields are configured, click the Save button.
An information message is displayed on saving the threat feed successfully.
.jpg)
Customize the IoC values
When the threat feed is saved, you can view and exclude one or more imported IoC values for each IoC type.
Go to the IoC Values tab.
There is a tab displayed for each imported IoC type.
Deselect one or more value(s) for any IoC type that you do not want the Sensors to monitor.
This is particularly useful when there are IoC values imported which might not indicate malicious traffic in your network environment, resulting in network outage due to one of the false positive IoC logs or alerts. For more information, see Handling traffic blocked by false positive IoCs.
.jpg)
Once done, click the Save IoC Values button.
You can view the excluded IoC value(s) on the Exclusions tab. The excluded values are not used for threat detection by the Sensor.
.png)
Assign the feed to Sensors
After the configuration of the threat feed, you must assign it to one or more Sensors. A single threat feed can be assigned to multiple Sensors.
Go to the Device Assignments tab.
It lists the available Sensor devices for the selected domain under Available Devices section.
Select one or more Sensors you want to assign to the thread feed created and click the
button to move the device to the Selected Devices section.You can use the
button to move any device back to the Available Devices section, or Reset button to start the device assignment process afresh..png)
Once you have assigned the required Sensor(s) to the threat feed and they are listed in the Selected Devices section, click the Save Assignments button.
This completes the configuration of a threat feed in the Manager. You can then configure Sensor alert logging mechanism for the configured feed based on IoC types imported.
Edit a threat feed in the Manager
To edit and update a threat feed entry in the Feed Configuration page -
Double-click the threat feed entry you want to edit.
The Configure Feed tab of the Feed Configuration page is displayed as default.
Update the fields on each of the tabs as required and save the changes.
Note
While updating details on the Configure Feed tab, all fields barring Name and Visibility can be updated. You need to reimport the JSON file containing the IoC types to save the feed.
Delete a threat feed in the Manager
To delete a threat feed entry in the Feed Configuration page -
Select the threat feed entry you want to delete.
Click the
icon.