- CheckMates
- :
- Products
- :
- Quantum
- :
- Threat Prevention
- :
- IOC feed using CSV or txt
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
IOC feed using CSV or txt
Dear All,
We have Check Point R81.10 security gateways, and we want to automate the blocking of malicious IPs and URLs gathered by the SOC team. We want the SOC team to add the malicious IPs and URLs to a separate server in a text file, and then we will link these files to our gateways using the IOC. Is there any documentation available that can help me achieve this?
Thanks
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Just to update, I did remote session with @Ihenock1011 and his colleague and I showed them exactly what I have configured in the lab, as well as good reference below:
https://support.checkpoint.com/results/sk/sk132193
Once again, as we discussed, please try upgrade to R81.20, as its recommended anyway and also, below are all the links I sent before, including new one we tested today.
Andy
ioc indicators links:
http://rules.emergingthreats.net/fwrules/emerging-Block-IPs.txt
https://feodotracker.abuse.ch/downloads/ipblocklist_recommended.txt
https://github.com/firehol/blocklist-ipsets
https://www.misp-project.org/feeds/
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
K, sounds good. I sort of figured that was the case, just wanted to clarify.
Thank you as always 🙂
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
This is covered in the Threat Prevention Admin Guide for the version. e.g.
Is there a particular issue that you're facing here or a unique requirement?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If you have a significant number of IoCs, I highly recommend upgrading to R81.20.
You also have Network Feed objects in R81.20, which allow for more flexible reporting and Network Feed objects can be directly used in the Access Policy.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
This is also a good reference SK: sk132193
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
What I didn't get from the SK is
How do I make the gateways refer to the CSV file?
Where should I put the CSV file, either on a file server or any server?
Lastly, can you share with me a sample CSV file that contains both optional and mandatory fields?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I can send you one tomorrow, as well as example of some fqdn's you can use, and best thing about is that they are dynamically updated. And yes, I agree with Phoneboy, R81.20 is the way to go if you plan to use this feature.
Best,
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hey mate,
As promised, here it is. Attached the screenshot, as well as the file.
Let me know if you are not clear and happy to do remote and show you my lab. Remember, you need EITHER av OR ab blade enabled for this to work.
Andy
http://rules.emergingthreats.net/fwrules/emerging-Block-IPs.txt
https://feodotracker.abuse.ch/downloads/ipblocklist_recommended.txt
https://github.com/firehol/blocklist-ipsets
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@the_rock Thanks a lot!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hope that was useful info? If not, let me know, we can do remote and I can show you more in my lab.
Best,
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@the_rockThat was helpful! If we could do a remote session, it would be much better for me. I could then clear up a lot of things.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Sure, what time zone you in?
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
GMT+3 EAT 8:00AM-12:00PM or 2:00PMto 5:00PM will be best.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
So its 2.35 pm now for you?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
K, messaged you offline
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Just to update, I did remote session with @Ihenock1011 and his colleague and I showed them exactly what I have configured in the lab, as well as good reference below:
https://support.checkpoint.com/results/sk/sk132193
Once again, as we discussed, please try upgrade to R81.20, as its recommended anyway and also, below are all the links I sent before, including new one we tested today.
Andy
ioc indicators links:
http://rules.emergingthreats.net/fwrules/emerging-Block-IPs.txt
https://feodotracker.abuse.ch/downloads/ipblocklist_recommended.txt
https://github.com/firehol/blocklist-ipsets
https://www.misp-project.org/feeds/
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hey boys,
Just a quick question...any idea if Check Point has recommended link of bad IP addresses that get updated automatically or is this more up to customer to find and use at their discretion?
Best,
Andy
I see links in the sk below, but not sure if there is anything else or not...
https://support.checkpoint.com/results/sk/sk132193
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Okay, you you looked into sk132193. There are many free and commercial IoCs from different sources, but I am not aware of anything Check Point would consider recommended per se.
The lists are quite different and vary per industry.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
K, sounds good. I sort of figured that was the case, just wanted to clarify.
Thank you as always 🙂
Andy
