The Central Management System appliance can receive indicators of compromise (IOCs) from the following custom feeds.
Third-party feeds send IOCs to the Central Management System appliance from a third-party (non-Trellix) product.
DTI feeds provide files from Trellix's Dynamic Threat Intelligence (DTI) cloud.
A single local feed sends IOCs to the Central Management System appliance from Network Security, Email Security — Server, File Protect, and Malware Analysis appliances. A local feed is a system-generated feed that is managed by the Central Management System appliance. You cannot upload, delete, edit, or download a local feed.
The IOCs from custom feeds are distributed to managed Network Security appliances in a standard format. You can create customized lists of IOCs received from these feeds and use them as a custom blacklist on the Central Management System appliance. The types of IOCs are URL indicators, IP address indicators, domain indicators, and indicators with hashes of malicious files. You can create a list of for each type of indicator, or you can combine them into a standard format called STIX (Structured Threat Information Expression). You configure the managed Network Security appliances to block or allow traffic that matches the custom blacklist. If traffic is blocked, you are notified that a block occurred. If traffic is not blocked, an alert is created and you are notified that a match occurred.
Only one master custom blacklist is created from all the feeds. This master blacklist is maintained on the Central Management System appliance and is copied to all the managed Network Security appliances.
Important
Enabling third-party feeds or the local feed on the Central Management System appliance can negatively impact the performance of the appliance.
Task list for managing custom IOC feeds
Complete the steps for managing custom IOC feeds in the following order:
Verify that the managed Network Security appliances are deployed in TAP mode or inline mode.
On the Central Management System appliance, enable custom IOC feeds. For details, see Enabling or disabling custom IOC feeds .
Create a flat file or XML-based file in STIX format that contains custom blacklist entries. Verify the file is accessible from the local desktop from which you access the Central Management System Web UI. For details about how to create a custom blacklist from a third-party feed, see Creating a custom blacklist from third-party feeds .
Upload the third-party feed blacklist to a Central Management System appliance. For details about how to upload a third-party feed, see Uploading a third-party feed .
View the details of the malware events that matched the name of the custom blacklist feed. For details, see Viewing custom feed details grouped by alert using the Web UI .