Despite reading for days, I feel like I'm missing something fundamental.
The TID option of FMC needs sources. Cisco doesn't provide sources? (That's a question, maybe I'm missing something).
I've seen recommendations to use AlienVault OTX and HailaTaxii both, I configured both, and they are working, but I feel like it must be very duplicative - I pulled all HailaTaxii so now have 12 sources, and a good part of the day is spent parsing updates.
Are they duplicative? Is there a "cisco" version of this? I have seen people refer to Talos, but that seems related to other rules, not TID?
I think it is very good that one can configure your own standard format sources, but it seems like being empty out-of-the-box is worrisome. I have all the licenses for Cisco databases and filtering, was there a TID feed I missed?
Which third party one(s) are you finding most useful, if any?
Thanks,
Linwood