<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: R81.20 and STIX File Imports (CISA) in Firewall &amp; Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-Security-Management/R81-20-and-STIX-File-Imports-CISA/m-p/227644#M54075</link>
    <description>&lt;P&gt;Looks like it's importing the file correctly.&lt;BR /&gt;Imported indicators will be enforced in Anti-Virus, so it's expected that will show.&lt;/P&gt;
&lt;P&gt;Not clear what it is you are expecting to see here.&lt;/P&gt;</description>
    <pubDate>Mon, 23 Sep 2024 23:23:13 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2024-09-23T23:23:13Z</dc:date>
    <item>
      <title>R81.20 and STIX File Imports (CISA)</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/R81-20-and-STIX-File-Imports-CISA/m-p/227632#M54074</link>
      <description>&lt;P&gt;Just starting to look into STIX files and getting our firewalls a little more smarter and importing feeds from outside sources.&amp;nbsp; My first task is to try and get the CISA alert STIX files imported.&amp;nbsp; I was hoping it was as easy as just importing the files but there looks to be specific CheckPoint values missing that is causing issues.&amp;nbsp; When I import the file, everything is assigned to the 'Anti-Virus' product and I assume that's why when I was testing with my IP, nothing was being detected.&amp;nbsp; I couldn't find a good example of how to get these categories set properly in my STIX file and/or if there was a way to easily massage the CISA (or other party) STIX files into a CheckPoint approved format?&lt;/P&gt;&lt;P&gt;For example, just playing with this latest notice and the STIX file attached:&amp;nbsp;&lt;A href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-249a" target="_blank" rel="noopener"&gt;https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-249a&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Was following this doc and see that IP should be set to Anti-Bot but just not sure how:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk132193" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk132193&lt;/A&gt;&lt;/P&gt;&lt;P&gt;See attached on how it imports.&lt;/P&gt;&lt;P&gt;We're running R81.20 for management and the gateways in the cluster.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Sep 2024 20:53:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/R81-20-and-STIX-File-Imports-CISA/m-p/227632#M54074</guid>
      <dc:creator>VikingsFan</dc:creator>
      <dc:date>2024-09-23T20:53:29Z</dc:date>
    </item>
    <item>
      <title>Re: R81.20 and STIX File Imports (CISA)</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/R81-20-and-STIX-File-Imports-CISA/m-p/227644#M54075</link>
      <description>&lt;P&gt;Looks like it's importing the file correctly.&lt;BR /&gt;Imported indicators will be enforced in Anti-Virus, so it's expected that will show.&lt;/P&gt;
&lt;P&gt;Not clear what it is you are expecting to see here.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Sep 2024 23:23:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/R81-20-and-STIX-File-Imports-CISA/m-p/227644#M54075</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-09-23T23:23:13Z</dc:date>
    </item>
    <item>
      <title>Re: R81.20 and STIX File Imports (CISA)</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/R81-20-and-STIX-File-Imports-CISA/m-p/227740#M54076</link>
      <description>&lt;P&gt;Hi PhoneBoy,&lt;/P&gt;&lt;P&gt;When the observables were loaded and I tested against my IP accessing a web server in our DMZ, there were no detects on my IP which made me believe that it is not working properly.&amp;nbsp; My theory was, after reading SK132193, the observables needed to be assigned the correct software blade.&amp;nbsp; For an IP, according to the SK, it should be on the Anti-Bot and not the Anti-Virus, which is what it defaulted to.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE border="1" cellspacing="2" cellpadding="4"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Observable Type&lt;/TD&gt;&lt;TD&gt;Software Blade&lt;/TD&gt;&lt;TD&gt;Full Software Blade Name&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;URL&lt;/TD&gt;&lt;TD&gt;AV/AB&lt;/TD&gt;&lt;TD&gt;Anti-Virus / Anti-Bot&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Domain&lt;/TD&gt;&lt;TD&gt;AV/AB&lt;/TD&gt;&lt;TD&gt;Anti-Virus / Anti-Bot&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;IP&lt;/TD&gt;&lt;TD&gt;AB&lt;/TD&gt;&lt;TD&gt;Anti-Bot&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;IP Range&lt;/TD&gt;&lt;TD&gt;AB&lt;/TD&gt;&lt;TD&gt;Anti-Bot&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;MD5&lt;/TD&gt;&lt;TD&gt;AV&lt;/TD&gt;&lt;TD&gt;Anti-Virus&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Mail-subject&lt;/TD&gt;&lt;TD&gt;AV/AB&lt;/TD&gt;&lt;TD&gt;Anti-Virus / Anti-Bot&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Mail-from&lt;/TD&gt;&lt;TD&gt;AV/AB&lt;/TD&gt;&lt;TD&gt;Anti-Virus / Anti-Bot&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Mail-to&lt;/TD&gt;&lt;TD&gt;AV/AB&lt;/TD&gt;&lt;TD&gt;Anti-Virus / Anti-Bot&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Mail-cc&lt;/TD&gt;&lt;TD&gt;AV/AB&lt;/TD&gt;&lt;TD&gt;Anti-Virus / Anti-Bot&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Mail-reply-to&lt;/TD&gt;&lt;TD&gt;AV/AB&lt;/TD&gt;&lt;TD&gt;Anti-Virus / Anti-Bot&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;SHA1&lt;/TD&gt;&lt;TD&gt;AV&lt;/TD&gt;&lt;TD&gt;Anti-Virus&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;SHA256&lt;/TD&gt;&lt;TD&gt;AV&lt;/TD&gt;&lt;TD&gt;Anti-Virus&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Snort&lt;/TD&gt;&lt;TD&gt;IPS&lt;/TD&gt;&lt;TD&gt;IPS&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Tue, 24 Sep 2024 11:12:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/R81-20-and-STIX-File-Imports-CISA/m-p/227740#M54076</guid>
      <dc:creator>VikingsFan</dc:creator>
      <dc:date>2024-09-24T11:12:38Z</dc:date>
    </item>
    <item>
      <title>Re: R81.20 and STIX File Imports (CISA)</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/R81-20-and-STIX-File-Imports-CISA/m-p/227744#M54077</link>
      <description>&lt;P&gt;I just did a CSV import with my IP and assigned it the Anti-Bot for the Product instead of the default Anti-Virus and I'm still not getting any detects when browsing to our web servers.&amp;nbsp; Maybe it doesn't work as I think it would?&amp;nbsp; Do the threat indicators detect/prevent inbound connections?&amp;nbsp; I did confirm that my Bot and Virus profiles have the 'Enable Indicator Scanning' checked.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Sep 2024 11:28:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/R81-20-and-STIX-File-Imports-CISA/m-p/227744#M54077</guid>
      <dc:creator>VikingsFan</dc:creator>
      <dc:date>2024-09-24T11:28:12Z</dc:date>
    </item>
    <item>
      <title>Re: R81.20 and STIX File Imports (CISA)</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/R81-20-and-STIX-File-Imports-CISA/m-p/227931#M54078</link>
      <description>&lt;P&gt;It's supposed to block inbound connections (as of R81), yes.&lt;BR /&gt;Recommend engaging with TAC here: &lt;A href="https://help.checkpoint.com" target="_blank"&gt;https://help.checkpoint.com&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Sep 2024 17:11:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/R81-20-and-STIX-File-Imports-CISA/m-p/227931#M54078</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-09-25T17:11:21Z</dc:date>
    </item>
  </channel>
</rss>

