Just starting to look into STIX files and getting our firewalls a little more smarter and importing feeds from outside sources. My first task is to try and get the CISA alert STIX files imported. I was hoping it was as easy as just importing the files but there looks to be specific CheckPoint values missing that is causing issues. When I import the file, everything is assigned to the 'Anti-Virus' product and I assume that's why when I was testing with my IP, nothing was being detected. I couldn't find a good example of how to get these categories set properly in my STIX file and/or if there was a way to easily massage the CISA (or other party) STIX files into a CheckPoint approved format?
For example, just playing with this latest notice and the STIX file attached: https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-249a
Was following this doc and see that IP should be set to Anti-Bot but just not sure how: https://support.checkpoint.com/results/sk/sk132193
See attached on how it imports.
We're running R81.20 for management and the gateways in the cluster.