McAfee Threat Intelligence Exchange (v2.0.25)
Connect to McAfee TIE using the McAfee DXL client.
- Author
- Cortex XSOAR
- Support
- xsoar
- URL
- https://www.paloaltonetworks.com/cortex
- Categories
- Data Enrichment & Threat Intelligence
Integrations (2)
- McAfee Threat Intelligence Exchange (Deprecated)
- McAfee Threat Intelligence Exchange v2
Playbooks (2)
- Search Endpoints By Hash - TIE
- TIE - IOC Hunt
README
Use the McAfee Threat Intelligence Exchange (TIE) integration to get file reputations and the systems that reference the files.
What does this content pack do?
- Retrieves threat intelligence data about files from global, and local sources.
- Determine which and when local systems have executed files.
- Manages threat intelligence data locally, giving the user the opportunity to set specific data about files.
Authentication
- McAfee Threat Intelligence uses the McAfee Data Exchange Layer (DXL) to be able to connect and retrieve data from multiple products and endpoints.
- The connection is done by creating certificates and configuring them in the ePO (McAfee ePolicy Orchestrator) server.