Automatically add threat intelligence to a TAXII collection
Learn how to automatically add threat intelligence to a TAXII server collection.
Before you begin
Role required:
- System Administrator (view, create or edit)
- sn_sec_tisc.admin (view)
Procedure
Navigate to All > Threat Intelligence Security Center > Administration.
Select Automated Flows.
Select Automatically add threat intelligence to a TAXII collection action link to view the respective rule details in the flow designer.
View the flow designer action for the following triggers:
Observable Created or Updated where (Type is IP address (V4), or Type is IP address (V6), or Type is Domain Name; and TISC Tags contains Add to: Sample Collection, and Reputation is Malicious, and Threat Score greater than or is 60Actions
Adds the record provided in the inputs to TAXII server collections configured in the selected template
Add Record to TAXII Server Collection
Add Records to TAXII Server Collection
End the flow for adding threat intelligence to a TAXII collection.
Automated TAXII server collection.
Parent Topic:Working with automated flows
Related topics
Automated sharing of high-risk IOC's with trusted partners
Create vulnerability assessment for zero day
Analyze, assess, and disseminate observables
Analyze and assess threat IoC’s
Vulnerability Management Support
Zero-day vulnerability tracking