About custom IOC feeds

Prev Next

The appliance can receive indicators of compromise (IOCs) from the following custom feeds:

  • DTI feeds provide files from Trellix's Dynamic Threat Intelligence (DTI) cloud.

  • Third-party feeds send files from a third-party (non-Trellix) product.

The following types of IOCs can be uploaded to appliances:

  • IP address indicators—IP addresses of suspicious or known malicious remote hosts.

  • URL indicators—Suspicious or known malicious URLs and RegEx URLs.

  • Hash files—MD5 or SHA-256 hashes for suspicious or known malicious files.

  • Domain indicators—Names of suspicious or known malicious domains.

You can create a flat-file list for each indicator type, or you can combine different types of indicators into a standard format called STIX (Structured Threat Information Expression).

IOCs received from third-party feeds can be combined into a custom blacklist, and the appliance can block or allow traffic that matches indicators in the custom blacklist. If traffic is blocked, you are notified that a block action was performed. If traffic is not blocked, an alert is created and you are notified that a match occurred.