Integrating NDR Console with Mandiant Threat Intelligence

Prev Next

You can integrate the Trellix NDR with Mandiant Threat Intelligence. This integration helps you:

  • Automate threat detection : Automatically run retroactive search on network metadata using up-to-date Mandiant Indicators of Compromise (IOCs).

  • Leverage custom intelligence: Enhance detection by using your own threat intelligence feeds in STIX or OpenIOC formats.

  • Improve incident response: Receive detailed THREAT_INTEL alerts with full intelligence reports when a threat is found.

This integration downloads the latest Mandiant Indicators of Compromise (IOCs) to the NDR. The console then searches your indexed network metadata for matches. When a match is found, the system creates a THREAT_INTEL alert. This alert includes a full intelligence report about the threat.

Before you begin

Ensure the following requirements are met: