<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IOCs upload to Secure Endpoint in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/iocs-upload-to-secure-endpoint/m-p/4562053#M6723</link>
    <description>Sorry, more than likely .csv format.&lt;BR /&gt;I would require the format of the table beforehand in order to upload&lt;BR /&gt;accordingly.&lt;BR /&gt;</description>
    <pubDate>Wed, 02 Mar 2022 12:06:20 GMT</pubDate>
    <dc:creator>larry.siegelman</dc:creator>
    <dc:date>2022-03-02T12:06:20Z</dc:date>
    <item>
      <title>IOCs upload to Secure Endpoint</title>
      <link>https://community.cisco.com/t5/endpoint-security/iocs-upload-to-secure-endpoint/m-p/4558737#M6695</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have hash values that I would like to upload to the Secure Endpoint platform.&lt;/P&gt;&lt;P&gt;Is there any logical publication showing how to do so?&lt;/P&gt;&lt;P&gt;I see that an XML file format is needed.&lt;/P&gt;&lt;P&gt;What are some samples, so it would match?&lt;/P&gt;</description>
      <pubDate>Thu, 24 Feb 2022 10:43:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/iocs-upload-to-secure-endpoint/m-p/4558737#M6695</guid>
      <dc:creator>larry.siegelman</dc:creator>
      <dc:date>2022-02-24T10:43:36Z</dc:date>
    </item>
    <item>
      <title>Re: IOCs upload to Secure Endpoint</title>
      <link>https://community.cisco.com/t5/endpoint-security/iocs-upload-to-secure-endpoint/m-p/4558977#M6697</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1305698"&gt;@larry.siegelman&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;the CloudIOC detections generated by backend engines are fully managed by Cisco. The customer cannot generate custom "Real Time IOC detections". You are able to do Endpoint IOC Scans. What do you want to do?&lt;BR /&gt;Greetings,&lt;BR /&gt;Thorsten&lt;/P&gt;</description>
      <pubDate>Thu, 24 Feb 2022 15:49:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/iocs-upload-to-secure-endpoint/m-p/4558977#M6697</guid>
      <dc:creator>Troja007</dc:creator>
      <dc:date>2022-02-24T15:49:41Z</dc:date>
    </item>
    <item>
      <title>Re: IOCs upload to Secure Endpoint</title>
      <link>https://community.cisco.com/t5/endpoint-security/iocs-upload-to-secure-endpoint/m-p/4559803#M6702</link>
      <description>&lt;P&gt;You can check the &lt;A href="https://docs.amp.cisco.com/Cisco%20Endpoint%20IOC%20Attributes.pdf" target="_self"&gt;Cisco Endpoint IOC Attributes&lt;/A&gt; document available from the &lt;A href="https://console.amp.cisco.com/docs" target="_self"&gt;Secure Endpoint Documentation&lt;/A&gt; portal. The document contains links to several examples in OpenIOC format. There are several other resources available online from various vendors related to the OpenIOC format including those found at &lt;A href="http://www.openioc.org/" target="_blank" rel="noopener"&gt;openioc.com&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Feb 2022 17:14:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/iocs-upload-to-secure-endpoint/m-p/4559803#M6702</guid>
      <dc:creator>johnosn</dc:creator>
      <dc:date>2022-02-25T17:14:03Z</dc:date>
    </item>
    <item>
      <title>Re: IOCs upload to Secure Endpoint</title>
      <link>https://community.cisco.com/t5/endpoint-security/iocs-upload-to-secure-endpoint/m-p/4560332#M6704</link>
      <description>Hello,&lt;BR /&gt;Thank you for the information, but that is not what I am looking for.&lt;BR /&gt;I have experience with other security platforms from other leading vendors,&lt;BR /&gt;and to upload hash files from threat feeds or from our national CIRT, is&lt;BR /&gt;much easier.&lt;BR /&gt;Why does Cisco have to make you jump through hoops in order to upload&lt;BR /&gt;hashes?&lt;BR /&gt;</description>
      <pubDate>Sun, 27 Feb 2022 04:42:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/iocs-upload-to-secure-endpoint/m-p/4560332#M6704</guid>
      <dc:creator>larry.siegelman</dc:creator>
      <dc:date>2022-02-27T04:42:20Z</dc:date>
    </item>
    <item>
      <title>Re: IOCs upload to Secure Endpoint</title>
      <link>https://community.cisco.com/t5/endpoint-security/iocs-upload-to-secure-endpoint/m-p/4560333#M6705</link>
      <description>I have experience with other security platforms from other leading vendors,&lt;BR /&gt;and to upload hash files from threat feeds or from our national CIRT, is&lt;BR /&gt;much easier.&lt;BR /&gt;Why does Cisco have to make you jump through hoops in order to upload&lt;BR /&gt;hashes?&lt;BR /&gt;</description>
      <pubDate>Sun, 27 Feb 2022 05:00:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/iocs-upload-to-secure-endpoint/m-p/4560333#M6705</guid>
      <dc:creator>larry.siegelman</dc:creator>
      <dc:date>2022-02-27T05:00:20Z</dc:date>
    </item>
    <item>
      <title>Re: IOCs upload to Secure Endpoint</title>
      <link>https://community.cisco.com/t5/endpoint-security/iocs-upload-to-secure-endpoint/m-p/4561270#M6714</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1305698"&gt;@larry.siegelman&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;I´m working on Feature Requests for Secure Endpoint. Just to be specific defining the Feature request.&lt;/P&gt;
&lt;P&gt;When uploading hashes from Threat Feeds, what should be the action?&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Generating an alert that the file has been seen?&lt;/LI&gt;
&lt;LI&gt;Block the execution of the file?&lt;/LI&gt;
&lt;LI&gt;Quarantine the file?&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Thanks and Greetings,&lt;BR /&gt;Thorsten&lt;/P&gt;</description>
      <pubDate>Tue, 01 Mar 2022 07:18:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/iocs-upload-to-secure-endpoint/m-p/4561270#M6714</guid>
      <dc:creator>Troja007</dc:creator>
      <dc:date>2022-03-01T07:18:12Z</dc:date>
    </item>
    <item>
      <title>Re: IOCs upload to Secure Endpoint</title>
      <link>https://community.cisco.com/t5/endpoint-security/iocs-upload-to-secure-endpoint/m-p/4561276#M6715</link>
      <description>Hello &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/547768"&gt;@Troja007&lt;/a&gt;&lt;BR /&gt;&lt;BR /&gt;If we can upload hashes, then I would expect that it would block the file&lt;BR /&gt;or executable from being able to propagate.&lt;BR /&gt;As with any other malware/IOC that gets blocked in our environment, these&lt;BR /&gt;too would be shown that their presence was blocked.&lt;BR /&gt;We already have Cisco threat Response to verify that it was not present.&lt;BR /&gt;</description>
      <pubDate>Tue, 01 Mar 2022 07:36:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/iocs-upload-to-secure-endpoint/m-p/4561276#M6715</guid>
      <dc:creator>larry.siegelman</dc:creator>
      <dc:date>2022-03-01T07:36:20Z</dc:date>
    </item>
    <item>
      <title>Re: IOCs upload to Secure Endpoint</title>
      <link>https://community.cisco.com/t5/endpoint-security/iocs-upload-to-secure-endpoint/m-p/4561639#M6719</link>
      <description>Hey Larry,&lt;BR /&gt;What format are the files you're trying to upload?  Is it something standard?&lt;BR /&gt;Ken&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 01 Mar 2022 19:41:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/iocs-upload-to-secure-endpoint/m-p/4561639#M6719</guid>
      <dc:creator>Ken Stieers</dc:creator>
      <dc:date>2022-03-01T19:41:20Z</dc:date>
    </item>
    <item>
      <title>Re: IOCs upload to Secure Endpoint</title>
      <link>https://community.cisco.com/t5/endpoint-security/iocs-upload-to-secure-endpoint/m-p/4561803#M6721</link>
      <description>Hi Ken,&lt;BR /&gt;&lt;BR /&gt;Yes, basically, hashes of recognized files.&lt;BR /&gt;I have experience with other globally leading vendors, where I was able to&lt;BR /&gt;upload, albeit to our direct environment, hash values.&lt;BR /&gt;</description>
      <pubDate>Wed, 02 Mar 2022 05:56:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/iocs-upload-to-secure-endpoint/m-p/4561803#M6721</guid>
      <dc:creator>larry.siegelman</dc:creator>
      <dc:date>2022-03-02T05:56:20Z</dc:date>
    </item>
    <item>
      <title>Re: IOCs upload to Secure Endpoint</title>
      <link>https://community.cisco.com/t5/endpoint-security/iocs-upload-to-secure-endpoint/m-p/4562047#M6722</link>
      <description>I meant csv, json, xml, stix, yara?&lt;BR /&gt;</description>
      <pubDate>Wed, 02 Mar 2022 11:58:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/iocs-upload-to-secure-endpoint/m-p/4562047#M6722</guid>
      <dc:creator>Ken Stieers</dc:creator>
      <dc:date>2022-03-02T11:58:20Z</dc:date>
    </item>
    <item>
      <title>Re: IOCs upload to Secure Endpoint</title>
      <link>https://community.cisco.com/t5/endpoint-security/iocs-upload-to-secure-endpoint/m-p/4562053#M6723</link>
      <description>Sorry, more than likely .csv format.&lt;BR /&gt;I would require the format of the table beforehand in order to upload&lt;BR /&gt;accordingly.&lt;BR /&gt;</description>
      <pubDate>Wed, 02 Mar 2022 12:06:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/iocs-upload-to-secure-endpoint/m-p/4562053#M6723</guid>
      <dc:creator>larry.siegelman</dc:creator>
      <dc:date>2022-03-02T12:06:20Z</dc:date>
    </item>
    <item>
      <title>Re: IOCs upload to Secure Endpoint</title>
      <link>https://community.cisco.com/t5/endpoint-security/iocs-upload-to-secure-endpoint/m-p/4562166#M6724</link>
      <description>&lt;P&gt;I guess I'm confused as to what the issue is...&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Outbreak Control/Custom detections, create or add to a current one... you can add SHAs there...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SCD.png" style="width: 985px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/145070iE87FFEB1B709A3A7/image-size/large?v=v2&amp;amp;px=999" role="button" title="SCD.png" alt="SCD.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Mar 2022 15:04:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/iocs-upload-to-secure-endpoint/m-p/4562166#M6724</guid>
      <dc:creator>Ken Stieers</dc:creator>
      <dc:date>2022-03-02T15:04:15Z</dc:date>
    </item>
    <item>
      <title>Re: IOCs upload to Secure Endpoint</title>
      <link>https://community.cisco.com/t5/endpoint-security/iocs-upload-to-secure-endpoint/m-p/4562185#M6725</link>
      <description>You know what, it says "Simple" and I never took it to be that!&lt;BR /&gt;How silly do I feel now? &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;Having said that, is there a required format for the file?&lt;BR /&gt;Any examples to download and use as a template?&lt;BR /&gt;</description>
      <pubDate>Wed, 02 Mar 2022 15:21:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/iocs-upload-to-secure-endpoint/m-p/4562185#M6725</guid>
      <dc:creator>larry.siegelman</dc:creator>
      <dc:date>2022-03-02T15:21:20Z</dc:date>
    </item>
    <item>
      <title>Re: IOCs upload to Secure Endpoint</title>
      <link>https://community.cisco.com/t5/endpoint-security/iocs-upload-to-secure-endpoint/m-p/4562246#M6726</link>
      <description>One SHA per line for a set of SHA's, they all get the same note...&lt;BR /&gt;Hey Torsten, and ehn would be to be able to pull the note from the CSV... so the SHA's get their own note.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 02 Mar 2022 16:32:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/iocs-upload-to-secure-endpoint/m-p/4562246#M6726</guid>
      <dc:creator>Ken Stieers</dc:creator>
      <dc:date>2022-03-02T16:32:20Z</dc:date>
    </item>
  </channel>
</rss>

