Set up feeds to retrieve indicators of compromise from remote sources. You can then use these feeds to generate watchlists, alarms, and reports that allow users to access related IOC activity in your environment.
On the system navigation tree, click System Properties.
Click → .
On the Main tab, enter the feed name.
On the Source tab, select the source data type and its connection credentials.
Note
The supported sources include Trellix Intelligent Sandbox and MITRE Threat Information Exchange (TAXII).
Click Connect to test the connection.
On the Frequency tab, identify how often the feed pulls the IOC files (pull frequency) and the daily trigger time.
Available pull frequencies include: every x minutes, daily, hourly, weekly, or monthly.
On the Watchlist tab, select which property or field in an IOC file to append to an existing watchlist.
You can add watchlists for any supported property or field.
If the watchlist you need does not yet exist, click Create New Watchlist. For more information, see the Set up cyber threat feed for domain.
On the Backtrace tab:
Select to analyze events, flows, or both.
Indicate how far back (in days) to analyze the events and flows.
Specify actions to take if the backtrace finds a data match.
For alarms, select an assignee and severity.
On the Main tab, select Enabled to activate the feed and click Finish.