Ensure that you have configured an inbox service and set a data collection name on the TAXII server.
Log on to the Intelligent Sandbox interface, then click → → and select Generate STIX report.
Click → → , then select Enable TAXII Communication.
In URL, type the address of your TAXII server.
Choose None or Basic based on the authentication requirement set for your server.
If you choose Basic, type the user name and password for authentication.
If your TAXII server requires TAXII client authentication, select Certificate Authentication Required.
Use Browse to select a certificate, then click Upload.
Note
The certificate must be in PEM format.
Merge the private key with your certificate.
Ensure that the certificate key-length is 2048 bytes or above.
Select Enable Discovery and do the following:
In Discover Service URL, type the URL for the discover service.
This allows Intelligent Sandbox to check for available TAXII services on the TAXII server.
In Collection URL, type the URL for the data collection service.
This allows Intelligent Sandbox to request information about available Data Collections on the TAXII server.
In Inbox Path, type the path of the managed inbox of your TAXII server.
Inbox Path can be read from response obtained from Discover Services.
In Collection Name, type the name of the collection where the STIX reports are delivered.
Collection Name can be read from response obtained from Discover Collection.
Click Test Connection to check the status of the connection between Intelligent Sandbox and the TAXII server.
The check returns the status of the following:
Inbox service on collection name.
Discovery service (if enabled)
Collection Service (if enabled)
Click Apply to save your configuration.
Once Intelligent Sandbox starts communicating with the TAXII server, the TAXII Status changes to the following:
UP – Last attempt to send STIX report to the TAXII server was successful.
DOWN – Last attempt to send STIX report to the TAXII server was unsuccessful. This status can also appear if the TAXII settings are not configured or incorrect.
UNKNOWN – Connection status is not yet verified by Intelligent Sandbox.