<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Automatic Adding of FBI/etc. Thread Indicators in Firewall &amp; Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Automatic-Adding-of-FBI-etc-Thread-Indicators/m-p/131612#M55893</link>
    <description>&lt;P&gt;That's one way to do it,&amp;nbsp;ioc_feeds is another.&lt;BR /&gt;See:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk132193&amp;amp;partition=Basic&amp;amp;product=Anti-Virus," target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk132193&amp;amp;partition=Basic&amp;amp;product=Anti-Virus,&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 13 Oct 2021 02:14:47 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2021-10-13T02:14:47Z</dc:date>
    <item>
      <title>Automatic Adding of FBI/etc. Thread Indicators</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Automatic-Adding-of-FBI-etc-Thread-Indicators/m-p/131599#M55892</link>
      <description>&lt;P&gt;On a regular basis we get emailed a list of threat indicators from the FBI and other CIBER organizations.&amp;nbsp; So when there are IP's or DNS names to block, we manually add them to our firewall rules.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I "thought" I saw somewhere there is a way to have automatic feeds to these and have the firewall updated automatically.&amp;nbsp; Do I recall correctly?&amp;nbsp; If so, is there any documentation on how to get this setup?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have read this:&lt;/P&gt;&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R80.40/WebAdminGuides/EN/CP_R80.40_ThreatPrevention_AdminGuide/Topics-TPG/Configuring_Threat_Indicators.htm?Highlight=ioc#Importin" target="_blank"&gt;Configuring Threat Indicators (checkpoint.com)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;But that is a manual process.&amp;nbsp; I am lokoing for a somewhat automatic process as possible.&lt;/P&gt;&lt;P&gt;Thanks for any suggestions/pointers.&lt;/P&gt;&lt;P&gt;Dennis&lt;/P&gt;</description>
      <pubDate>Tue, 12 Oct 2021 20:03:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Automatic-Adding-of-FBI-etc-Thread-Indicators/m-p/131599#M55892</guid>
      <dc:creator>Dennis_Longneck</dc:creator>
      <dc:date>2021-10-12T20:03:12Z</dc:date>
    </item>
    <item>
      <title>Re: Automatic Adding of FBI/etc. Thread Indicators</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Automatic-Adding-of-FBI-etc-Thread-Indicators/m-p/131612#M55893</link>
      <description>&lt;P&gt;That's one way to do it,&amp;nbsp;ioc_feeds is another.&lt;BR /&gt;See:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk132193&amp;amp;partition=Basic&amp;amp;product=Anti-Virus," target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk132193&amp;amp;partition=Basic&amp;amp;product=Anti-Virus,&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Oct 2021 02:14:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Automatic-Adding-of-FBI-etc-Thread-Indicators/m-p/131612#M55893</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-10-13T02:14:47Z</dc:date>
    </item>
    <item>
      <title>Re: Automatic Adding of FBI/etc. Thread Indicators</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Automatic-Adding-of-FBI-etc-Thread-Indicators/m-p/132742#M55894</link>
      <description>&lt;P&gt;Do you know if there's any advantage or disadvantage from either using the .txt feeds (Provider has a domain.txt and IP.txt) or the STIX feeds?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Either choices seem like they can be automated with that ioc_feeds, but just wanted to double check since I have no experience in this.&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 27 Oct 2021 23:04:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Automatic-Adding-of-FBI-etc-Thread-Indicators/m-p/132742#M55894</guid>
      <dc:creator>r1der</dc:creator>
      <dc:date>2021-10-27T23:04:09Z</dc:date>
    </item>
    <item>
      <title>Re: Automatic Adding of FBI/etc. Thread Indicators</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Automatic-Adding-of-FBI-etc-Thread-Indicators/m-p/132743#M55895</link>
      <description>&lt;P&gt;Not as far as I remember.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Oct 2021 23:40:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Automatic-Adding-of-FBI-etc-Thread-Indicators/m-p/132743#M55895</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-10-27T23:40:05Z</dc:date>
    </item>
    <item>
      <title>Re: Automatic Adding of FBI/etc. Thread Indicators</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Automatic-Adding-of-FBI-etc-Thread-Indicators/m-p/132763#M55896</link>
      <description>&lt;P&gt;Check Point's own InfinitySoC allows you to manage your own threat feed.&amp;nbsp; IOC management is still in Early Access, but our testing has gone very well.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Oct 2021 06:54:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Automatic-Adding-of-FBI-etc-Thread-Indicators/m-p/132763#M55896</guid>
      <dc:creator>Ruan_Kotze</dc:creator>
      <dc:date>2021-10-28T06:54:31Z</dc:date>
    </item>
    <item>
      <title>Re: Automatic Adding of FBI/etc. Thread Indicators</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Automatic-Adding-of-FBI-etc-Thread-Indicators/m-p/132879#M55897</link>
      <description>&lt;P&gt;Did you get this setup Dennis? I plan to do the same with a feed from MS-ISAC. Curious to see whether STIX or the TXT files would be best ingested into CP. Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 29 Oct 2021 17:00:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Automatic-Adding-of-FBI-etc-Thread-Indicators/m-p/132879#M55897</guid>
      <dc:creator>r1der</dc:creator>
      <dc:date>2021-10-29T17:00:22Z</dc:date>
    </item>
    <item>
      <title>Re: Automatic Adding of FBI/etc. Thread Indicators</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Automatic-Adding-of-FBI-etc-Thread-Indicators/m-p/132880#M55898</link>
      <description>&lt;P&gt;I did not get it setup.&amp;nbsp; &amp;nbsp; Didn't see a way to automatically have it done....even with the MS-ISAC ones.&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Oct 2021 17:09:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Automatic-Adding-of-FBI-etc-Thread-Indicators/m-p/132880#M55898</guid>
      <dc:creator>Dennis_Longneck</dc:creator>
      <dc:date>2021-10-29T17:09:24Z</dc:date>
    </item>
    <item>
      <title>Re: Automatic Adding of FBI/etc. Thread Indicators</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Automatic-Adding-of-FBI-etc-Thread-Indicators/m-p/132896#M55899</link>
      <description>&lt;P&gt;From what I know IOC Feeds are only blocking outgoing connections and not incoming ones. Which is sometimes not what you want...&lt;/P&gt;</description>
      <pubDate>Sat, 30 Oct 2021 04:12:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Automatic-Adding-of-FBI-etc-Thread-Indicators/m-p/132896#M55899</guid>
      <dc:creator>HristoGrigorov</dc:creator>
      <dc:date>2021-10-30T04:12:28Z</dc:date>
    </item>
    <item>
      <title>Re: Automatic Adding of FBI/etc. Thread Indicators</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Automatic-Adding-of-FBI-etc-Thread-Indicators/m-p/132898#M55900</link>
      <description>&lt;P&gt;In R81 it also blocks outgoing connections.&lt;BR /&gt;Even in pre-R81, while the outgoing connection is not blocked, the reply traffic from those IPs will be blocked.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 30 Oct 2021 05:22:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Automatic-Adding-of-FBI-etc-Thread-Indicators/m-p/132898#M55900</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-10-30T05:22:35Z</dc:date>
    </item>
    <item>
      <title>Re: Automatic Adding of FBI/etc. Thread Indicators</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Automatic-Adding-of-FBI-etc-Thread-Indicators/m-p/132901#M55901</link>
      <description>&lt;P&gt;When using feeds, are the blocks shown in the logs?&amp;nbsp; Additionally if we are asked to blacklist an IP, how can we easily confirm this is already taken care of?&lt;/P&gt;
&lt;P&gt;Are there any performance overheads?&lt;/P&gt;</description>
      <pubDate>Sat, 30 Oct 2021 11:04:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Automatic-Adding-of-FBI-etc-Thread-Indicators/m-p/132901#M55901</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2021-10-30T11:04:45Z</dc:date>
    </item>
    <item>
      <title>Re: Automatic Adding of FBI/etc. Thread Indicators</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Automatic-Adding-of-FBI-etc-Thread-Indicators/m-p/132902#M55902</link>
      <description>&lt;P&gt;Yes, because the feeds are added in AV/AB blades so you see them in TP logs. I didn't see any specific overheads by using the feature.&lt;/P&gt;</description>
      <pubDate>Sat, 30 Oct 2021 14:07:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Automatic-Adding-of-FBI-etc-Thread-Indicators/m-p/132902#M55902</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2021-10-30T14:07:19Z</dc:date>
    </item>
    <item>
      <title>Re: Automatic Adding of FBI/etc. Thread Indicators</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Automatic-Adding-of-FBI-etc-Thread-Indicators/m-p/132910#M55903</link>
      <description>&lt;P&gt;nice,&amp;nbsp; when I was talking about overhead, I assume the gateway itself pulls the feed therefore connectivity would go via slowpath, interestingly if this was a VSX setup, is the tool aware of VSs?&amp;nbsp; Similar to log_exporter?&lt;/P&gt;</description>
      <pubDate>Sat, 30 Oct 2021 21:34:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Automatic-Adding-of-FBI-etc-Thread-Indicators/m-p/132910#M55903</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2021-10-30T21:34:49Z</dc:date>
    </item>
    <item>
      <title>Re: Automatic Adding of FBI/etc. Thread Indicators</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Automatic-Adding-of-FBI-etc-Thread-Indicators/m-p/133232#M55904</link>
      <description>&lt;P&gt;We are running R80.40 and I have recently setup ioc_feeds with the MS-ISAC Taxii/Stix feeds. My lack of familiarity with Stix/Taxii/ioc_feeds probably quadrupled the time spent, but the short story is I had to use python/cabby (&lt;A href="https://github.com/eclecticiq/cabby" target="_blank"&gt;https://github.com/eclecticiq/cabby&lt;/A&gt;) and script a process to pull the feeds and parse out domain/url/ip data into a csv file for ioc_feeds to pull in. What I discovered was that Checkpoint will ingest a &lt;EM&gt;single&lt;/EM&gt; Stix Package in txt format, but will not ingest a feed/file that consists of multiple Stix Packages rolled up into a single document, which is what I ended up with. I probably could have tinkered with the xml tags to see if I could get the CP to ingest, but not knowing what the CP was looking for, decided to stick with what I could easily decipher in the docs (csv). We comment each ioc with the associated feed so we can see it in the logs. This is not elegant, but it is functional. If there's a better way I'd be all ears....&lt;/P&gt;</description>
      <pubDate>Thu, 04 Nov 2021 13:22:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Automatic-Adding-of-FBI-etc-Thread-Indicators/m-p/133232#M55904</guid>
      <dc:creator>skidsteerpilot</dc:creator>
      <dc:date>2021-11-04T13:22:23Z</dc:date>
    </item>
    <item>
      <title>Re: Automatic Adding of FBI/etc. Thread Indicators</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Automatic-Adding-of-FBI-etc-Thread-Indicators/m-p/135079#M55905</link>
      <description>&lt;P&gt;The feed is being pulled with “slow path” Infrastructure but the enforcement itself is running with fastpath.&lt;/P&gt;
&lt;P&gt;IOC feeds infra isn’t aware to the VSX gateways and behave for each one as a separated one.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 28 Nov 2021 07:51:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Automatic-Adding-of-FBI-etc-Thread-Indicators/m-p/135079#M55905</guid>
      <dc:creator>asafav</dc:creator>
      <dc:date>2021-11-28T07:51:54Z</dc:date>
    </item>
    <item>
      <title>Re: Automatic Adding of FBI/etc. Thread Indicators</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Automatic-Adding-of-FBI-etc-Thread-Indicators/m-p/135133#M55906</link>
      <description>&lt;P&gt;Check Point NDR Smart Intel is a Generally Available solution that automates indicator input feed ingestion and distribution to Check Point and 3rd party gateways. It is also the basis for Infinity Vision SOC's IOC Management facility.&lt;/P&gt;
&lt;P&gt;Customers who purchase Infinity SOC are automatically entitled to use NDR applications.&lt;/P&gt;
&lt;P&gt;Check out&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/CloudGuard-NDR/NDR-Smart-Intel-User-Guide/m-p/131434" target="_blank"&gt;https://community.checkpoint.com/t5/CloudGuard-NDR/NDR-Smart-Intel-User-Guide/m-p/131434&lt;/A&gt;&amp;nbsp;for details.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Nov 2021 09:32:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Automatic-Adding-of-FBI-etc-Thread-Indicators/m-p/135133#M55906</guid>
      <dc:creator>Nir_Naaman</dc:creator>
      <dc:date>2021-11-29T09:32:39Z</dc:date>
    </item>
    <item>
      <title>Re: Automatic Adding of FBI/etc. Thread Indicators</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Automatic-Adding-of-FBI-etc-Thread-Indicators/m-p/165174#M55907</link>
      <description>&lt;P&gt;Sorry, I'm just getting into the STIX space. I was emailed one from the FBI, but it was in STIX 2.0 format. I manually imported it into the Threat Tools-&amp;gt;Indicators, but got a bunch of warnings. I then did a quick google,&amp;nbsp; which showed Checkpoint keeps saying that they only support 1.0.&amp;nbsp; Is Checkpoint ever going to upgrade to the current standard (which is actually 2.1)?&lt;/P&gt;</description>
      <pubDate>Wed, 14 Dec 2022 13:34:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Automatic-Adding-of-FBI-etc-Thread-Indicators/m-p/165174#M55907</guid>
      <dc:creator>Benjamin_Weiss</dc:creator>
      <dc:date>2022-12-14T13:34:29Z</dc:date>
    </item>
    <item>
      <title>Re: Automatic Adding of FBI/etc. Thread Indicators</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Automatic-Adding-of-FBI-etc-Thread-Indicators/m-p/165211#M55908</link>
      <description>&lt;P&gt;An RFE with the local Check Point office is recommended here.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Dec 2022 19:13:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Automatic-Adding-of-FBI-etc-Thread-Indicators/m-p/165211#M55908</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-12-14T19:13:15Z</dc:date>
    </item>
    <item>
      <title>Re: Automatic Adding of FBI/etc. Thread Indicators</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Automatic-Adding-of-FBI-etc-Thread-Indicators/m-p/168792#M55909</link>
      <description>&lt;P&gt;Horizon NDR Intel now supports STIX/TAXII v2.* for both automated input feeds and Load from file.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2023 18:06:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Automatic-Adding-of-FBI-etc-Thread-Indicators/m-p/168792#M55909</guid>
      <dc:creator>Nir_Naaman</dc:creator>
      <dc:date>2023-01-23T18:06:04Z</dc:date>
    </item>
  </channel>
</rss>

