ThreatConnect
Protocol | Information Collected | Used For |
---|---|---|
ThreatConnect API | Malware Domain, IP, URL and Hash | Detect threats for Security and Compliance |
Configuring ThreatConnect
Create an API Key to be used for FortiSIEM communication.
The details are here:
https://kb.threatconnect.com/customer/en/portal/articles/2188549-creating-user-accounts
- Log in to your ThreatConnect portal as an administrative user.
- Go to My Profile > ORG Settings.
- Click Create API User.
These credentials will be created:
- Access ID
- Secret Key
- Note the Organization Name. You will need it in a later step.
- ThreatConnect contains many threat feeds. If you want to get specific threatfeeds, then you must know the threat feeds that are available for your account. You can see these feeds by navigating to Browse > Indicators > My ThreatConnect > Intelligent Sources.
Configuring FortiSIEM to Download IOCs from ThreatConnect
Use the Access ID and Secret Key that were created in the previous section to enable FortiSIEM access.
FortiSIEM can provide the following IOCs from ThreatConnect:
- Malware Domain
- Malware IP
- Malware URL
- Malware Hash
Follow these steps to set up Malware Domain downloads from ThreatConnect.
- Login to FortiSIEM.
- Go to RESOURCE > Malware Domain > ThreatConnect Malware Domain.
- Click More > Update. Select Update via API.
- Enter the following fields
- Set User Name to Access ID (Step 3a above).
- Set Password to Secret Key (Step 3b above).
- Set Data Format to STIX-TAXII.
- For Collection:, you have two choices:
- To get all threatfeeds - enter All:<Organization Name> (Step 4 above), or
- To get specific threatfeeds, enter comma-separated values of threatfeeds (obtained from Step 6 above).
- Set Data Update = Incremental
- Choose Start time.
- Choose Recurrence pattern.
- Click Save.
Downloading Other IOCs
The steps for configuring FortiSIEM to download other IOCs are identical, except for the following details:
- Malware IP—Navigate to RESOURCE > Malware Domain > ThreatConnect Malware IP
- Malware URL—Navigate to RESOURCE > Malware Domain > ThreatConnect Malware URL
- Malware Hash—Navigate to RESOURCE > Malware Domain > ThreatConnect Malware Hash