Custom IOCs

Prev Next

The Central Management System platform can receive indicators of compromise (IOCs) from third-party feeds and distribute them to managed appliances in a standardized format. You can create customized lists of IOCs received from third-party feeds and use them as customized blacklists on the Central Management System platform. The types of IOCs are URL indicators, IP address indicators, domain indicators, and indicators with hash values for malicious files. You can create a list for each type of indicator, or you can combine them into a standardized format called Structured Threat Information Expression (STIX). You configure the managed appliances to block or allow traffic that matches the customized blacklist. If traffic is blocked, you will be notified that a block occurred. If traffic is not blocked, an alert is created, and you will be notified that a match occurred.

A locally generated feed contains the feed files that are provided from the Dynamic Threat Intelligence (DTI) Cloud. Only one master customized blacklist is created from all the feeds. This master blacklist is maintained on the Central Management System platform, and it is copied to all the managed appliances.

You can also use the Web UI to manage custom IOCs. See the Central Management System Administration Guide for more information.

This section covers the following: