The appliance can receive indicators of compromise (IOCs) from the following custom feeds:
DTI feeds provide files from Trellix's Dynamic Threat Intelligence (DTI) cloud.
Third-party feeds send files from a third-party (non-Trellix) product.
The following types of IOCs can be uploaded to appliances:
IP address indicators—IP addresses of suspicious or known malicious remote hosts.
URL indicators—Suspicious or known malicious URLs and RegEx URLs.
Hash files—MD5 or SHA-256 hashes for suspicious or known malicious files.
Domain indicators—Names of suspicious or known malicious domains.
You can create a flat-file list for each indicator type, or you can combine different types of indicators into a standard format called STIX (Structured Threat Information Expression).
IOCs received from third-party feeds can be combined into a custom blacklist, and the appliance can block or allow traffic that matches indicators in the custom blacklist. If traffic is blocked, you are notified that a block action was performed. If traffic is not blocked, an alert is created and you are notified that a match occurred.