<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IOC import in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-import/m-p/27123#M58432</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you, Dameon. I saw that some filds were not supported. But was confused where is the exact problem, because they file should be standardized.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We will open the case.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Milica&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 15 Sep 2018 05:58:12 GMT</pubDate>
    <dc:creator>Milica_Spasic</dc:creator>
    <dc:date>2018-09-15T05:58:12Z</dc:date>
    <item>
      <title>IOC import</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-import/m-p/27121#M58430</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have tried to import IoC downloaded from IBM xforce exchange web site in order to prevent some malicious activities, but if had failed. I'm using stix format (example file is attached). I receive following error:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/70301_pastedImage_1.png" /&gt;&lt;/P&gt;&lt;P&gt;Our management is on 80.20 version.&lt;/P&gt;&lt;P&gt;Any idea what couses the problem?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;Milica&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Sep 2018 12:33:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-import/m-p/27121#M58430</guid>
      <dc:creator>Milica_Spasic</dc:creator>
      <dc:date>2018-09-14T12:33:50Z</dc:date>
    </item>
    <item>
      <title>Re: IOC import</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-import/m-p/27122#M58431</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is it the R80.20 EA or R80.20.M1?&lt;/P&gt;&lt;P&gt;Anyway, the errors seem to be somewhat obvious:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Several fields in the XML file aren't supported by us--those are ignored.&lt;/LI&gt;&lt;LI&gt;Since confidence, severity, and product aren't included in this XML (which we use), we specify defaults.&lt;/LI&gt;&lt;LI&gt;From this file, it seems we cannot determine the IOCs, or it's not in the format we expect.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Assuming it's R80.20.M1, I would open a TAC case.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 15 Sep 2018 00:31:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-import/m-p/27122#M58431</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-09-15T00:31:17Z</dc:date>
    </item>
    <item>
      <title>Re: IOC import</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-import/m-p/27123#M58432</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you, Dameon. I saw that some filds were not supported. But was confused where is the exact problem, because they file should be standardized.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We will open the case.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Milica&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 15 Sep 2018 05:58:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-import/m-p/27123#M58432</guid>
      <dc:creator>Milica_Spasic</dc:creator>
      <dc:date>2018-09-15T05:58:12Z</dc:date>
    </item>
  </channel>
</rss>

