Hello,
I have enabled TAXII Server via Threat Intel Management and configured the TAXII on my FortiGate devices too. The Malicious entries are being synced to FortiGate configurations however facing few issues and need help on below:
1- We had a requirement to add additional picklist types for filehashes i.e. Vhash, SSDEEP, Authentihash for blocking. And added the values too in TIM. It got synced to FortiGate however shows invalid entries unlike other valid entries for Filehash MD5, SHA1. Please guide what is missing here.
2-For some FortiGate devices, Threat intel feeds are replicated to some FortiGate devices and are not replicated on some. Please guide what can be the issue and any logs or troubleshooting steps for the same.
@Deep We need to troubleshoot the FortiGate to understand how the feeds are being consumed and mapped. We also need to replicate the same scenario in our lab. Please give us some time to do this.
Apologies for the delayed response.
Appreciate your reply @sahirrao .
1-Can you please guide on which hash types are they when you say "Please map the VHash, SSDEEP, and Authentihash hashes to the appropriate hash types supported by the STIX specification"
2-The usual IOCs - IP, Domain, etc.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.