You can integrate the Trellix NDR with Mandiant Threat Intelligence. This integration helps you:
Automate threat detection : Automatically run retroactive search on network metadata using up-to-date Mandiant Indicators of Compromise (IOCs).
Leverage custom intelligence: Enhance detection by using your own threat intelligence feeds in STIX or OpenIOC formats.
Improve incident response: Receive detailed THREAT_INTEL alerts with full intelligence reports when a threat is found.
This integration downloads the latest Mandiant Indicators of Compromise (IOCs) to the NDR. The console then searches your indexed network metadata for matches. When a match is found, the system creates a THREAT_INTEL alert. This alert includes a full intelligence report about the threat.
Before you begin
Ensure the following requirements are met:
Mandiant Threat Intelligence subscription: A valid subscription with the necessary API license keys is required. Without a valid license, a license error notification will be displayed on the Intel Feeds and Scheduling page.
For subscription inquiries, contact Trellix Customer Support: https://www.trellix.com/en-us/support.html.
API documentation is available at: https://docs.fireeye.com/docs/index.html#IS