Enable IOC Communication from Threat Intelligence to the Device
Integrating a device with Threat Intelligence (Intelligence Hub) enables them to communicate with each other, a process referred to as internal remediation. This section describes the general internal remediation process, where indicators of compromise (IOCs) are communicated from Threat Intelligence to the device.
For information specific to each device, see the section for that device.
In Threat Intelligence, IOCs are gathered in IOC groups, which are then transmitted to user devices. IOC groups can gather IOCs from various sources, and some of those sources may be user-created rules. These rules enable greater control over which IOCs are transmitted to a user device.
IOC groups are created in the Data Connectors > Threat Intelligence > Integrations page.
The process of creating IOC groups is described in full in the Automate Internal Remediationsection of the Threat Intelligence User Guide*.
For pull devices, a unique IOC URL must be copied from Threat Intelligence and configured in the device.
For push devices, there are various ways to receive IOCs from Threat Intelligence.
Each group (or in some cases, each defined device) has a unique identifier which, when shared with the user device, enables IOCs to be transmitted.
Some IOC groups have a unique URL. This URL is copied from Threat Intelligence to the management console of the device.
Some devices have device details that are the same for all IOC groups. These details are copied from Threat Intelligence to the management console of the device.