The Central Management System platform can receive indicators of compromise (IOCs) from third-party feeds and distribute them to managed appliances in a standardized format. You can create customized lists of IOCs received from third-party feeds and use them as customized blacklists on the Central Management System platform. The types of IOCs are URL indicators, IP address indicators, domain indicators, and indicators with hash values for malicious files. You can create a list for each type of indicator, or you can combine them into a standardized format called Structured Threat Information Expression (STIX). You configure the managed appliances to block or allow traffic that matches the customized blacklist. If traffic is blocked, you will be notified that a block occurred. If traffic is not blocked, an alert is created, and you will be notified that a match occurred.
A locally generated feed contains the feed files that are provided from the Dynamic Threat Intelligence (DTI) Cloud. Only one master customized blacklist is created from all the feeds. This master blacklist is maintained on the Central Management System platform, and it is copied to all the managed appliances.
You can also use the Web UI to manage custom IOCs. See the Central Management System Administration Guide for more information.
This section covers the following:
Adding or updating custom IOC files. For more information, see Add or update a custom IOC file request .
Deleting custom IOC files. For more information, see Delete a custom IOC file request .
Listing custom IOC files. For more information, see List custom IOC files request .
Downloading custom IOC files. For more information, see Download a custom IOC file request .
Adding a new intel feed. For more information, see Add intel feed .
Reading an intel feed. For more information, see Read intel feed .
Updating intel feed metadata. For more information, see Update intel feed metadata .
Updating feed payload. For more information, see Update intel feed payload .
Downloading an intel feed payload. For more information, see Download intel feed payload .
Deleting one or more intel feeds. For more information, see Delete one or more feeds .
Adding a YARA rule file. For more information, see Add a YARA rule .
Deleting a YARA rule file. For more information, see Delete a YARA rule .
Adding a custom Snort rule file. For more information, see Add a custom snort rule .
Deleting a custom Snort rule file. For more information, see Delete a custom snort rule .
Downloading a custom Snort rule file. For more information, see Download a custom snort rule file .
Downloading a YARA rule file. For more information, see Download a YARA rule file .
Listing a YARA rule. For more information, see List a YARA rule .
Retrieving the IOC for a specific alert. For more information, see IOC for an alert request.