02-24-2022 02:43 AM
Hello,
I have hash values that I would like to upload to the Secure Endpoint platform.
Is there any logical publication showing how to do so?
I see that an XML file format is needed.
What are some samples, so it would match?
02-24-2022 07:49 AM
Hello @larry.siegelman ,
the CloudIOC detections generated by backend engines are fully managed by Cisco. The customer cannot generate custom "Real Time IOC detections". You are able to do Endpoint IOC Scans. What do you want to do?
Greetings,
Thorsten
02-26-2022 09:00 PM
02-25-2022 09:14 AM
You can check the Cisco Endpoint IOC Attributes document available from the Secure Endpoint Documentation portal. The document contains links to several examples in OpenIOC format. There are several other resources available online from various vendors related to the OpenIOC format including those found at openioc.com.
02-26-2022 08:42 PM
02-28-2022 11:18 PM
Hello @larry.siegelman ,
I´m working on Feature Requests for Secure Endpoint. Just to be specific defining the Feature request.
When uploading hashes from Threat Feeds, what should be the action?
Thanks and Greetings,
Thorsten
02-28-2022 11:36 PM
03-01-2022 11:41 AM
03-01-2022 09:56 PM
03-02-2022 03:58 AM
03-02-2022 04:06 AM
03-02-2022 07:04 AM
I guess I'm confused as to what the issue is...
Outbreak Control/Custom detections, create or add to a current one... you can add SHAs there...
03-02-2022 07:21 AM
03-02-2022 08:32 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide