Learn how to automatically add threat intelligence to a TAXII server collection.
Antes de Iniciar
Role required:
- System Administrator (view, create or edit)
- sn_sec_tisc.admin (view)
Procedimento
-
Navigate to .
-
Select .
-
Select Automatically add threat intelligence to a TAXII collection action link to view the respective rule details in the flow designer.
-
View the flow designer action for the following triggers:
Observable Created or Updated where (Type is IP address (V4), or Type is IP address (V6), or Type is Domain Name; and TISC Tags contains Add to: Sample Collection, and Reputation is Malicious, and Threat Score greater than or is 60
-
Actions
Adds the record provided in the inputs to TAXII server collections configured in the selected template
-
Add Record to TAXII Server Collection
-
Add Records to TAXII Server Collection
-
End the flow for adding threat intelligence to a TAXII collection.