Once the CLI configuration is complete, scheduling, monitoring, and management of the intelligence feeds are performed through the NDR Console Web UI.
Schedule IOC searches
You can configure up to two daily search schedules for new IOCs from your enabled feeds.
Important
Your two search schedules must be 12 hours apart.
Log in to the NDR Console Web UI.
Navigate to Manage >Intel Feeds and Scheduling.
Click SEARCH SCHEDULE to open the configuration window.
Configure Schedule 1:
Time: Set the hour and minute (in UTC) for the search to begin.
Lookback: Specify the period (1-30 days) of indexed metadata to search against. The default is 14 days. Note: Lookback periods greater than 14 days can significantly increase search time.
Indicator Preview Time: Set a delay (1-6 hours) between the IOC download and the start of the search. The default is 1 hour. This provides a window to manually review and manage indicators before they are used in a search (see section 5.3).
Click Update Schedule to save the settings for Schedule 1.
To add a second schedule, check the Enable Schedule 2 box and configure its parameters.
Click SAVE SCHEDULE to save all changes.
Enabling and disabling intel feeds
You can enable or disable both the Mandiant feed and your custom feeds directly from the Web UI.
Navigate to Manage > Intel Feeds and Scheduling.
In the Intel Feeds table, locate the feed you wish to manage.
Use the ON/OFF toggle switch to enable or disable the feed.
Managing Mandiant Threat Intelligence IOCs
The Manage Recent IOCs table provides a view of the indicators received in the most recent download, allowing you to manage them before the next scheduled search begins. From this table, you can perform the following actions:
View Active Indicators: Review all IOCs from the last download.
Enable/Disable All: Use the Enable All or Disable All buttons to include or exclude all downloaded indicators from the next search.
Manually Select Indicators: Individually check or uncheck specific indicators to control which ones are used in the search.
Download Intelligence Report: For a specific indicator, download the full Mandiant Threat Intelligence report to understand the associated threat actor and context.
Export to CSV: Create and download a CSV file containing all indicators from the last download.
Pivot to Mandiant Portal: Use the view link next to an indicator to open the Mandiant Threat Intelligence portal for deeper analysis.
Configure Schedule 1 and Schedule 2 using the instructions provided in Scheduling Mandiant Threat Intelligence IOC downloads.
Manually select the indicators you want to apply to the next scheduled NDR search, or click Enable All to apply the indicators to the next scheduled search, or Disable All to exclude all the downloaded indicators from the next scheduled search.