Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Ihenock1011
Advisor
Jump to solution

IOC feed using CSV or txt

Dear All,

We have Check Point R81.10 security gateways, and we want to automate the blocking of malicious IPs and URLs gathered by the SOC team. We want the SOC team to add the malicious IPs and URLs to a separate server in a text file, and then we will link these files to our gateways using the IOC. Is there any documentation available that can help me achieve this?

Thanks

0 Kudos
2 Solutions

Accepted Solutions
the_rock
MVP Diamond
MVP Diamond

Just to update, I did remote session with @Ihenock1011 and his colleague and I showed them exactly what I have configured in the lab, as well as good reference below:

https://support.checkpoint.com/results/sk/sk132193

Once again, as we discussed, please try upgrade to R81.20, as its recommended anyway and also, below are all the links I sent before, including new one we tested today.

Andy

https://sc1.checkpoint.com/documents/R80.40/WebAdminGuides/EN/CP_R80.40_ThreatPrevention_AdminGuide/...

https://community.checkpoint.com/t5/Management/Importing-Indicator-Error-quot-Indicator-in-row-1-has...

https://community.checkpoint.com/t5/Security-Gateways/R81-10-External-IOC-processing-failed/m-p/2087...

ioc indicators links:

http://rules.emergingthreats.net/fwrules/emerging-Block-IPs.txt

https://feodotracker.abuse.ch/downloads/ipblocklist_recommended.txt

https://github.com/firehol/blocklist-ipsets

https://www.misp-project.org/feeds/

 

 

Best,
Andy
"Have a great day and if its not, change it"

View solution in original post

0 Kudos
the_rock
MVP Diamond
MVP Diamond

K, sounds good. I sort of figured that was the case, just wanted to clarify.

Thank you as always 🙂

Andy

Best,
Andy
"Have a great day and if its not, change it"

View solution in original post

0 Kudos
23 Replies
Chris_Atkinson
MVP Platinum CHKP MVP Platinum CHKP
MVP Platinum CHKP

This is covered in the Threat Prevention Admin Guide for the version. e.g.

https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_ThreatPrevention_AdminGuide/...

Is there a particular issue that you're facing here or a unique requirement?

CCSM R77/R80/ELITE
0 Kudos
PhoneBoy
Admin
Admin

If you have a significant number of IoCs, I highly recommend upgrading to R81.20.
You also have Network Feed objects in R81.20, which allow for more flexible reporting and Network Feed objects can be directly used in the Access Policy.

0 Kudos
CaseyB
Advisor

This is also a good reference SK: sk132193 

0 Kudos
Ihenock1011
Advisor

What I didn't get from the SK is

  1. How do I make the gateways refer to the CSV file?

  2. Where should I put the CSV file, either on a file server or any server?

Lastly, can you share with me a sample CSV file that contains both optional and mandatory fields?

0 Kudos
the_rock
MVP Diamond
MVP Diamond

I can send you one tomorrow, as well as example of some fqdn's you can use, and best thing about is that they are dynamically updated. And yes, I agree with Phoneboy, R81.20 is the way to go if you plan to use this feature.

Best,

Andy

Best,
Andy
"Have a great day and if its not, change it"
0 Kudos
the_rock
MVP Diamond
MVP Diamond
0 Kudos
Ihenock1011
Advisor

@the_rock Thanks a lot!

0 Kudos
the_rock
MVP Diamond
MVP Diamond

Hope that was useful info? If not, let me know, we can do remote and I can show you more in my lab.

Best,

Andy

Best,
Andy
"Have a great day and if its not, change it"
0 Kudos
Ihenock1011
Advisor

@the_rockThat was helpful! If we could do a remote session, it would be much better for me. I could then clear up a lot of things.

0 Kudos
the_rock
MVP Diamond
MVP Diamond

Sure, what time zone you in?

Andy

Best,
Andy
"Have a great day and if its not, change it"
0 Kudos
Ihenock1011
Advisor

GMT+3 EAT  8:00AM-12:00PM or  2:00PMto 5:00PM will be best. 

0 Kudos
the_rock
MVP Diamond
MVP Diamond

So its 2.35 pm now for you?

Best,
Andy
"Have a great day and if its not, change it"
0 Kudos
Ihenock1011
Advisor

Yes

0 Kudos
the_rock
MVP Diamond
MVP Diamond

K, messaged you offline

Best,
Andy
"Have a great day and if its not, change it"
0 Kudos
the_rock
MVP Diamond
MVP Diamond

Just to update, I did remote session with @Ihenock1011 and his colleague and I showed them exactly what I have configured in the lab, as well as good reference below:

https://support.checkpoint.com/results/sk/sk132193

Once again, as we discussed, please try upgrade to R81.20, as its recommended anyway and also, below are all the links I sent before, including new one we tested today.

Andy

https://sc1.checkpoint.com/documents/R80.40/WebAdminGuides/EN/CP_R80.40_ThreatPrevention_AdminGuide/...

https://community.checkpoint.com/t5/Management/Importing-Indicator-Error-quot-Indicator-in-row-1-has...

https://community.checkpoint.com/t5/Security-Gateways/R81-10-External-IOC-processing-failed/m-p/2087...

ioc indicators links:

http://rules.emergingthreats.net/fwrules/emerging-Block-IPs.txt

https://feodotracker.abuse.ch/downloads/ipblocklist_recommended.txt

https://github.com/firehol/blocklist-ipsets

https://www.misp-project.org/feeds/

 

 

Best,
Andy
"Have a great day and if its not, change it"
0 Kudos
the_rock
MVP Diamond
MVP Diamond

Hey boys,

@PhoneBoy @_Val_ 

 

Just a quick question...any idea if Check Point has recommended link of bad IP addresses that get updated automatically or is this more up to customer to find and use at their discretion? 

Best,

Andy

I see links in the sk below, but not sure if there is anything else or not...

https://support.checkpoint.com/results/sk/sk132193

 

 
Best,
Andy
"Have a great day and if its not, change it"
0 Kudos
_Val_
Admin
Admin

Okay, you you looked into sk132193. There are many free and commercial IoCs from different sources, but I am not aware of anything Check Point would consider recommended per se.

The lists are quite different and vary per industry.

(1)
the_rock
MVP Diamond
MVP Diamond

K, sounds good. I sort of figured that was the case, just wanted to clarify.

Thank you as always 🙂

Andy

Best,
Andy
"Have a great day and if its not, change it"
0 Kudos
speedbot33
Contributor

Did you try test feed before adding them as Indicators though? I;ve tried and says "test failed. No data was found in the feed".

Gateway has connectivity to site.

0 Kudos
the_rock
MVP Diamond
MVP Diamond

I did. yes.

Best,
Andy
"Have a great day and if its not, change it"
0 Kudos
speedbot33
Contributor

Well, for some reason my gateway shows that error message. Is there a difference between adding these feeds under Indicators vs using a Network feed object and placing it as src & dst in a Threat prevention policy?

0 Kudos
the_rock
MVP Diamond
MVP Diamond

I only tested this on R82 latest jumbo, but dont think it makes any difference.

Best,
Andy
"Have a great day and if its not, change it"
0 Kudos
PhoneBoy
Admin
Admin

Indicators are primarily for Threat Prevention purposes.
The file format is specific (CSV). 

Network Feed objects can be used for Threat Prevention, but they are mainly for Access Control.
The file format can either be a flat file (one indicator per line) or parseable JSON.

They are different files and use a different validation process.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events