TAXII 2 Feed
Ingests indicator feeds from TAXII 2.0 and 2.1 servers.
- Category
- Data Enrichment & Threat Intelligence
- Pack
- FeedTAXII
Configuration parameters
- feed — Fetch indicators
- feedReputation — Indicator Reputation
- feedReliability — Source Reliability (required)
- tlp_color — Traffic Light Protocol Color
- feedExpirationPolicy —
- feedExpirationInterval —
- feedFetchInterval — Feed Fetch Interval
- feedBypassExclusionList — Bypass exclusion list
- url — Discovery Service URL (e.g. https://example.net/taxii2) (required)
- credentials — Username / API Key
- default_api_root — API Root to Use
- collection_to_fetch — Collection Name To Fetch Indicators From
- feedIncremental — Incremental Feed
- fetch_full_feed — Full Feed Fetch
- limit — Max Indicators Per Fetch (disabled for Full Feed Fetch)
- initial_interval — First Fetch Time
- objects_to_fetch — STIX Objects To Fetch
- creds_certificate — Certificate File as Text
- certificate — Certificate File as Text
- key — Key File as Text
- limit_per_request — Max STIX Objects Per Poll
- observation_operator_mode — Complex Observation Mode
- update_custom_fields — Update custom fields
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
- feedTags — Tags
- enrichmentExcluded — Enrichment Excluded
Commands (3)
- taxii2-get-collections — Gets the list of collections from the discovery service.
- taxii2-get-indicators — Allows you to test your feed and to make sure you can fetch indicators successfuly.
- taxii2-reset-fetch-indicators — WARNING: This command will reset your fetch history.