<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Would you please be so kind in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/spam-feed-in-security-intelligence/m-p/2911855#M1030323</link>
    <description>&lt;P&gt;Would you please be so kind to elaborate (for a Snort newbie) where do you check all of that stuff . I'm also interested in what happens with spam and if there is something we can do about it .&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Much appreciated. Thank you&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 05 Jul 2016 16:23:25 GMT</pubDate>
    <dc:creator>Dusan Vuckovic</dc:creator>
    <dc:date>2016-07-05T16:23:25Z</dc:date>
    <item>
      <title>Spam feed in Security Intelligence</title>
      <link>https://community.cisco.com/t5/network-security/spam-feed-in-security-intelligence/m-p/2911853#M1030317</link>
      <description>&lt;P&gt;I use firepower v.5.4.1 on ASA 5516. I see huge amout of malware comming via mail (smtp connection). Almost every malware detection is only retrospective. It means malware reached customer mail servers and maybe users mail-boxes too. IP addresses of senders of malware messages (.zip files) are all listed as spam senders in senderbase.org or other anti-spam lists.&lt;/P&gt;
&lt;P&gt;Firepower Security Intelligence has feed and one of the category is Spam. But there is only 32k of ip addresses. I see some match and block on this list, but majority of malware from spam IP senders passed and is detected only hours or days later by retrospective.&lt;/P&gt;
&lt;P&gt;Could somebody suggest me reliable spam list (list of spammers IP addresses) which can be used as 3rd party list and can be downloaded as custom list? Or event better: is there any feed (not only static list) which can be used as Firepower Security Intelligence object?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 13:03:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/spam-feed-in-security-intelligence/m-p/2911853#M1030317</guid>
      <dc:creator>tpospisil</dc:creator>
      <dc:date>2019-03-12T13:03:01Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/spam-feed-in-security-intelligence/m-p/2911854#M1030320</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;As of now, we just have the static list in security intelligence but if you are observing&lt;/P&gt;
&lt;P&gt;some spam ip's being bypassed, you can open a TAC case so that we can investigate it further&amp;nbsp;&lt;/P&gt;
&lt;P&gt;and have the feed updated on our end.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Rate if it helps.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Ankita&lt;/P&gt;</description>
      <pubDate>Fri, 01 Jul 2016 10:08:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/spam-feed-in-security-intelligence/m-p/2911854#M1030320</guid>
      <dc:creator>ankojha</dc:creator>
      <dc:date>2016-07-01T10:08:25Z</dc:date>
    </item>
    <item>
      <title>Would you please be so kind</title>
      <link>https://community.cisco.com/t5/network-security/spam-feed-in-security-intelligence/m-p/2911855#M1030323</link>
      <description>&lt;P&gt;Would you please be so kind to elaborate (for a Snort newbie) where do you check all of that stuff . I'm also interested in what happens with spam and if there is something we can do about it .&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Much appreciated. Thank you&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2016 16:23:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/spam-feed-in-security-intelligence/m-p/2911855#M1030323</guid>
      <dc:creator>Dusan Vuckovic</dc:creator>
      <dc:date>2016-07-05T16:23:25Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/spam-feed-in-security-intelligence/m-p/2911856#M1030325</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;You can check the spam static list under /var/sf/si_urldownload and if you do&amp;nbsp;&lt;/P&gt;
&lt;P&gt;cat of the uuid , you will see the list of url or ip's in the list.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;You can follow the document to have better understanding :&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/firesight/541/user-guide/FireSIGHT-System-UserGuide-v5401/AC-Events.html&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Rate if it helps.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Ankita&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jul 2016 07:31:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/spam-feed-in-security-intelligence/m-p/2911856#M1030325</guid>
      <dc:creator>ankojha</dc:creator>
      <dc:date>2016-07-06T07:31:55Z</dc:date>
    </item>
    <item>
      <title>Thank you . Much appreciated.</title>
      <link>https://community.cisco.com/t5/network-security/spam-feed-in-security-intelligence/m-p/2911857#M1030329</link>
      <description>&lt;P&gt;Thank you . Much appreciated.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jul 2016 14:24:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/spam-feed-in-security-intelligence/m-p/2911857#M1030329</guid>
      <dc:creator>Dusan Vuckovic</dc:creator>
      <dc:date>2016-07-06T14:24:51Z</dc:date>
    </item>
    <item>
      <title>Static list is not a problem.</title>
      <link>https://community.cisco.com/t5/network-security/spam-feed-in-security-intelligence/m-p/2911858#M1030330</link>
      <description>&lt;P&gt;Static list is not a problem. But it's poor content. Cisco owns intelligence sources (senderbase.org, ironport's source ....), but on firepower spam list is like a joke. Firepower services get passed hundreds of malware files (as it later marks as retrospective) and all of IPaddr of senders is listed on senderbase.org with poor mail reputation.&lt;/P&gt;
&lt;P&gt;This is big confusion for customer: every morning opens firepower console and get list of passed malware, received from known malware senders.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jul 2016 07:19:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/spam-feed-in-security-intelligence/m-p/2911858#M1030330</guid>
      <dc:creator>tpospisil</dc:creator>
      <dc:date>2016-07-13T07:19:43Z</dc:date>
    </item>
    <item>
      <title>I have good experience with</title>
      <link>https://community.cisco.com/t5/network-security/spam-feed-in-security-intelligence/m-p/2911859#M1030334</link>
      <description>&lt;P&gt;I have good experience with the Security Intel feeds. &amp;nbsp;In addition, i added the Cisco Talos, feed, too. &amp;nbsp;In addition, we have our own internal Security Analysts intel feed. &amp;nbsp;No issues, so far. &amp;nbsp;Good metrics and reporting.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jul 2016 18:12:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/spam-feed-in-security-intelligence/m-p/2911859#M1030334</guid>
      <dc:creator>Ed Padilla Jr</dc:creator>
      <dc:date>2016-07-15T18:12:35Z</dc:date>
    </item>
    <item>
      <title>Could you be more specific,</title>
      <link>https://community.cisco.com/t5/network-security/spam-feed-in-security-intelligence/m-p/2911860#M1030336</link>
      <description>&lt;P&gt;Could you be more specific, please? Where I can find theese feeds and how can I use it in Firepower.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jul 2016 06:07:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/spam-feed-in-security-intelligence/m-p/2911860#M1030336</guid>
      <dc:creator>tpospisil</dc:creator>
      <dc:date>2016-07-18T06:07:28Z</dc:date>
    </item>
    <item>
      <title>Hello ,</title>
      <link>https://community.cisco.com/t5/network-security/spam-feed-in-security-intelligence/m-p/2911861#M1030338</link>
      <description>&lt;P&gt;Hello ,&lt;/P&gt;
&lt;P&gt;In order to update the Security Intelligence Feed, choose&amp;nbsp;&lt;STRONG&gt;Objects &amp;gt; Object Management&lt;/STRONG&gt;. Choose&amp;nbsp;the &lt;STRONG&gt;Security Intelligence&lt;/STRONG&gt; option from the left panel, and click &lt;STRONG&gt;Update Feeds&lt;/STRONG&gt;. If you want to update your custom feed or you want to create a custom list, click&amp;nbsp;&lt;STRONG&gt;Add Security Intelligence&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.cisco.com/c/dam/en/us/support/docs/security/firesight-management-center/118490-technote-firesight-02.png" class="show-image-alone" title="Related image, diagram or screenshot."&gt;&lt;IMG src="http://www.cisco.com/c/dam/en/us/support/docs/security/firesight-management-center/118490-technote-firesight-02.png" /&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Rate if this post helps you&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Jetsy&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jul 2016 06:18:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/spam-feed-in-security-intelligence/m-p/2911861#M1030338</guid>
      <dc:creator>Jetsy Mathew</dc:creator>
      <dc:date>2016-07-18T06:18:02Z</dc:date>
    </item>
    <item>
      <title>As I wrote in my opening post</title>
      <link>https://community.cisco.com/t5/network-security/spam-feed-in-security-intelligence/m-p/2911862#M1030340</link>
      <description>&lt;P&gt;As I wrote in my opening post, I use this buit-in feed. But these are poor. Because I receive tens of malware file per day. From IP addresses, which are known to Cisco (senderbase.org) as malware senders, but not included in built-in feeds. I am looking for third party feed to include to firepower which will contain IP's from senderbase.org (or similar) database.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jul 2016 06:23:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/spam-feed-in-security-intelligence/m-p/2911862#M1030340</guid>
      <dc:creator>tpospisil</dc:creator>
      <dc:date>2016-07-18T06:23:52Z</dc:date>
    </item>
  </channel>
</rss>

