Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
FortiHelp
New Contributor II

FortiEDR Threat Intelligence connector

Dears,

 

Does anyone have threat intelligence feed connector configuration with FortiEDR? Like 

 

URL: 

Collection ID: 

Authentication: 

 

 

 

 

BR,

 

5 REPLIES 5
FortiHelp
New Contributor II

Dear xskurti,

I have followed this document. What I asked that I needed URL and collection ID and Authentication fields 

 

BR

mvatansever
New Contributor II

Dear @FortiHelp 

You need a TAXII server; first, you need to set up a TAXII platform infrastructure. To serve as an example, I am sharing the FortiSOAR TAXII server configuration:

https://docs.fortinet.com/document/fortisoar/1.0.1/taxii2-threat-intel-feed/880/taxii2-threat-intel-...

Afterwards, you can either add a global feed or add your own IoCs. Then, you can add a FortiEDR Threat Intelligence connector as shown below:

URL: https://taxiiserver.blabla.com/api/taxii/1/collections/<datasetId>/objects/<objectId>

For example, object id: 5f686a25-5464-4ae5-bbd3-bf9b02f5d402
For example, dataset id: database

Basic Auth with username and password or REST API user

 

Regards,

FortiHelp

Dear Mvatansever,

Do you know of any global feeds? Can I reach out to them to get all this information and make the integration?

 

BR,

 

 

mvatansever

Dear @FortiHelp ,

 

You can view the Global Feed lists that can be integrated into FortiSOAR through the Content Hub: https://fortisoar.contenthub.fortinet.com//list.html?contentType=all&searchContent=Feed

You need to collect the IoC data published in the Global Feed lists on a central Taxii server and then share it with FortiEDR from there.

 

Regards,

Mehmet Vatansever

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors