FortiSIEM Discussions
HugoPinto
Contributor

Integrate Minemeld (Palo Alto) with FortiSIEM and FortiGuard

What is minemeld?

Minemeld is an IOC Aggregator, its used for EDL (External Dynamic List), it will collect IOC(s) from OTX, FortiGuard, join together and reduce duplicate entry's, then EDL will distribute to SIEM, Firewall, etc. the output can be in STIXX/TAXI, CSV, etc..

How to Push FortiGuard IOC, for separate the threats?

We will Push IOC(s) from the Fortiguard, for then separate the indicator for Threat Type, like APT Attack, Malware Post Infection.

1 REPLY 1
premchanderr
Staff
Staff

Hi @HugoPinto ,


You would need to setup a Custom threat feed for MineMeld.

 

The below document can has detailed steps on this:

https://help.fortinet.com/fsiem/7-2-3/Online-Help/HTML5_Help/Importing_malware_ip_information.htm

Regards,
Prem Chander R
Announcements

Welcome to your new Fortinet Community!

You'll find your previous forum posts under "Forums"