Pull IOCs from the Rapid7 TAXII server
You can pull enriched IOCs (Indicators of Compromise) into third-party security devices using the Rapid7 TAXII server (STIX/TAXII v1.1 and v2.0 are supported). The TAXII server is defined in Threat Intelligence as an external cloud device.
The following enrichment data is included:
- IOC Type
- First seen
- Last seen
- Reported feeds
- Severity
- Feed confidence level
- User tags
- System tags
- Threat Actor relation
- Malware relation
- Campaign relation
IOC groups can consist of:
- Domains
- URLs
- IP addresses
- File hashes
- Email addresses
Define the Rapid7 TAXII server integration
You can define a TAXII server to pull IOCs.
Before you begin, ensure that you have the API key, account ID, and appliance key .
To define a TAXII server:
-
From the Command Platform, go to Data Connectors > Threat Intelligence > Integrations.
-
Click Cloud.
-
Click Add new device.
-
In the Add New Cloud Device dialog box, define the Rapid7 TAXII server:
- Type a user-defined name for the device.
The name can contain a maximum of 50 letters, spaces, numbers, and underscores. - For the device type, select Rapid7 TAXII Server.
- Select the STIX version to support
v1.1orv2.0. - You can change the IOCs limit for the TAXII server (default is 100,000).
- Type a user-defined name for the device.
-
Click Add.
The new device is added to the cloud integrations device list. A red dot next to the device name indicates that communication has not yet been established. The dot changes to green once the device is synchronized. -
Display the device details required to connect to your security device:
- From the Threat Intelligence (Intelligence Hub) > Integrations > Cloud page, select the TAXII integration.
- At the top of the screen, click Device Details.
- From the Device Details dialog, you will need the Discovery URL. In addition, you need the API key, account ID, and appliance key . Copy this information into the management console of the security device.