Working with URLhaus Threat Feed
The following sections describe how to work with URLhaus malware URLs.
Download URLHaus Malware URLs
- Go to Resources > Malware URLs, select the URLHaus Malware URL folder.
- Click Configure (
). In the Update Malware dialog box, then select Update via API. - Click Edit (
) in the URL row. -
In the URL field, check if URL is valid. If not, then edit it.
If your Threat Feed is hosted on a Web Server and it needs a certificate, then the Web Server Certificate must be imported into FortiSIEM key store. Please follow the steps here from the Configuring CA Certificates Guide.
- Leave User Name, Password empty.
- Plugin Name is provided by default.
- Select a Data Update process. Selecting Full means FortiSIEM will download all data. If Incremental is selected, FortiSIEM will download from the latest recorded update date.
- Click Save.
- Schedule the download. See Specifying a Schedule.
- Check the folder 5 minutes after the scheduled time. Downloaded results should be displayed.
Specifying a Schedule
-
Click the + icon next to Schedule.
-
Enter values for the following options:
-
Time Range specifies start time (within the day) and the duration of the scheduling window. Select a UTC time and a corresponding location from the drop-down lists.
-
Recurrence Pattern specifies if and how the window will repeat.
Recurrence Pattern
Steps
Once -
Select the specific date in Start From.
Daily -
Select the interval of days or Every weekday.
-
Select the Start From date for Recurrence Range, then either End after the number of occurrences, and End by date, or No end date to continue the recurrence forever.
Weekly -
Select the interval of weeks or select particular days of the week.
-
Select the Start From date for Recurrence Range, then either End after the number of occurrences, and End by date, or No end date to continue the recurrence forever.
Monthly
-
Select the days and months from the drop-down lists.
-
Select the Start From date for Recurrence Range, then either End after the number of occurrences, and End by date, or No end date to continue the recurrence forever.
-
-
-
Click Save to apply the changes.
Verifying Scheduled Download is Successful
To verify that the scheduled download is successful, navigate to the appropriate top Resources > Malware IOC level, i.e. Resources > Malware IPs for Malware IP Threat Feed, Resources > Domain for Malware Domain Threat Feed, ... and check your Feed's row. When the scheduled download has occurred and is successful, the Status column will show Normal, and the Indicators column will show number of Malware IOCs.