<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unit 42 Palo Alto  integration with SIEM particularly ? in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/unit-42-palo-alto-integration-with-siem-particularly/m-p/1220379#M7879</link>
    <description>&lt;P&gt;Navigate to&amp;nbsp;&lt;A href="https://stix2.unit42.org" target="_blank"&gt;https://stix2.unit42.org&lt;/A&gt;&lt;SPAN data-ogsc="black" data-ogsb="white"&gt;&lt;A id="x_m_7801028442992494659OWAddd46645-2bff-aad0-c026-fccd31dd582d" title="https://urldefense.proofpoint.com/v2/url?u=https-3A__stix2.unit42.org_taxii_&amp;amp;d=DwMFaQ&amp;amp;c=V9IgWpI5PvzTw83UyHGVSoW3Uc1MFWe5J8PTfkrzVSo&amp;amp;r=JfdIyW7mPPBnkEtE1RpS0eUbppbccKCUzvE_QEp8-dg&amp;amp;m=rSVJxu1MPv0cIvn0pDshRxXP92qRk6QDNi_RbgT4JqM97ps-5YNPnWuf1vmj6Txa&amp;amp;s=3aN2l-5iFw-2gF5C8L37wVqEbr8SzsOtCSSw3c97ezU&amp;amp;e=" href="https://urldefense.proofpoint.com/v2/url?u=https-3A__stix2.unit42.org_taxii_&amp;amp;d=DwMFaQ&amp;amp;c=V9IgWpI5PvzTw83UyHGVSoW3Uc1MFWe5J8PTfkrzVSo&amp;amp;r=JfdIyW7mPPBnkEtE1RpS0eUbppbccKCUzvE_QEp8-dg&amp;amp;m=rSVJxu1MPv0cIvn0pDshRxXP92qRk6QDNi_RbgT4JqM97ps-5YNPnWuf1vmj6Txa&amp;amp;s=3aN2l-5iFw-2gF5C8L37wVqEbr8SzsOtCSSw3c97ezU&amp;amp;e=" data-auth="NotApplicable" data-linkindex="3" data-ogsc="" data-ogsb="white" target="_blank"&gt;&lt;/A&gt;. Create an account with email address (username) and password. (I created an API key, but I'm not sure that's necessary. It doesn't get used to authenticate from Sentinel.) Note the following details:&lt;/SPAN&gt;&lt;/P&gt;
&lt;TABLE id="x_m_7801028442992494659x_table_0" data-ogsb="white"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TH data-ogsb="rgb(88, 96, 106)"&gt;
&lt;DIV data-ogsc="black"&gt;&lt;SPAN&gt;Description&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/TH&gt;
&lt;TH data-ogsb="rgb(88, 96, 106)"&gt;
&lt;DIV data-ogsc="black"&gt;&lt;SPAN&gt;TAXII Discovery Service URL&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/TH&gt;
&lt;TH data-ogsb="rgb(88, 96, 106)"&gt;
&lt;DIV data-ogsc="black"&gt;&lt;SPAN&gt;TAXII API root&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/TH&gt;
&lt;TH data-ogsb="rgb(88, 96, 106)"&gt;
&lt;DIV data-ogsc="black"&gt;&lt;SPAN&gt;TAXII Collection ID&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/TH&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;DIV data-ogsc="black"&gt;Unit 42 Adversary Playbooks&lt;/DIV&gt;
&lt;/TD&gt;
&lt;TD&gt;&lt;A href="https://stix2.unit42.org/taxii/" target="_blank"&gt;https://stix2.unit42.org/taxii/&lt;/A&gt;&lt;/TD&gt;
&lt;TD&gt;
&lt;DIV data-ogsc="black"&gt;playbooks&lt;/DIV&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;DIV data-ogsc="black"&gt;[playbooks GUID]&lt;/DIV&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;DIV data-ogsc="black"&gt;Unit 42 Reports&lt;/DIV&gt;
&lt;/TD&gt;
&lt;TD&gt;&lt;A href="https://stix2.unit42.org/taxii/" target="_blank"&gt;https://stix2.unit42.org/taxii/&lt;/A&gt;&lt;/TD&gt;
&lt;TD&gt;
&lt;DIV data-ogsc="black"&gt;reports&lt;/DIV&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;DIV data-ogsc="black"&gt;[reports GUID]&lt;/DIV&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;DIV data-ogsc="black" data-ogsb="white"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV data-ogsc="black" data-ogsb="white"&gt;Navigate to&amp;nbsp;&lt;A href="https://stix2.unit42.org/taxii/" target="_blank"&gt;https://stix2.unit42.org/taxii/&lt;/A&gt;&amp;nbsp;and authenticate with the same username and password. Observe the api_roots in the JSON response:&lt;/DIV&gt;
&lt;DIV data-ogsc="black" data-ogsb="white"&gt;
&lt;BLOCKQUOTE&gt;
&lt;DIV data-ogsc="black"&gt;{ &amp;nbsp;"api_roots": [ &amp;nbsp; &amp;nbsp;"&lt;A href="https://stix2.unit42.org/playbooks/" target="_blank"&gt;https://stix2.unit42.org/playbooks/&lt;/A&gt;", &amp;nbsp; &amp;nbsp;"&lt;A href="https://stix2.unit42.org/reports/" target="_blank"&gt;https://stix2.unit42.org/reports/&lt;/A&gt;" &amp;nbsp;], &amp;nbsp;"contact": "&lt;A href="https://unit42.paloaltonetworks.com/" target="_blank"&gt;https://unit42.paloaltonetworks.com/&lt;/A&gt;", &amp;nbsp;"default": "&lt;A href="https://stix2.unit42.org/playbooks/" target="_blank"&gt;https://stix2.unit42.org/playbooks/&lt;/A&gt;", &amp;nbsp;"description": "Indicators from Palo Alto Networks Unit 42", &amp;nbsp;"host": "&lt;A href="https://stix2.unit42.org/" target="_blank"&gt;https://stix2.unit42.org/&lt;/A&gt;", &amp;nbsp;"title": "Unit 42 TAXII 2.0 Server" }&lt;/DIV&gt;
&lt;/BLOCKQUOTE&gt;
&lt;/DIV&gt;
&lt;DIV data-ogsc="black" data-ogsb="white"&gt;In Microsoft Sentinel, ensure the Threat Intelligence solution is enabled. Ensure the&amp;nbsp;Threat intelligence - TAXII connector is installed and open its connector page. Configure two TAXII servers with the following information:&lt;/DIV&gt;
&lt;DIV data-ogsc="black" data-ogsb="white"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV data-ogsc="black" data-ogsb="white"&gt;Friendly name (for server):&amp;nbsp;&lt;SPAN&gt;Unit42Reports&lt;/SPAN&gt;&lt;BR /&gt;API root URL:&amp;nbsp;&lt;A href="https://stix2.unit42.org/reports/" target="_blank"&gt;https://stix2.unit42.org/reports/&lt;/A&gt;&lt;BR /&gt;Collection ID: [reports GUID]&lt;BR /&gt;Username: [Unit 42 account username]&lt;BR /&gt;Password: [Unit 42 account password]&lt;BR /&gt;Import indicators: [choose best option for your context]&lt;BR /&gt;Polling frequency: [choose best option for your context]&amp;nbsp;&lt;/DIV&gt;
&lt;DIV data-ogsc="black" data-ogsb="white"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV data-ogsc="black" data-ogsb="white"&gt;
&lt;DIV data-ogsc="black" data-ogsb="white"&gt;Friendly name (for server): &lt;SPAN&gt;Unit42AdversaryPlaybooks&lt;/SPAN&gt;&lt;BR /&gt;API root URL:&amp;nbsp;&lt;A href="https://stix2.unit42.org/playbooks/" target="_blank"&gt;https://stix2.unit42.org/playbooks/&lt;/A&gt;&lt;BR /&gt;Collection ID: [playbooks GUID]&lt;BR /&gt;Username: [Unit 42 account username]&lt;BR /&gt;Password: [Unit 42 account password]&lt;BR /&gt;Import indicators: [choose best option for your context]&lt;BR /&gt;Polling frequency: [choose best option for your context]&lt;/DIV&gt;
&lt;/DIV&gt;</description>
    <pubDate>Thu, 13 Feb 2025 15:22:46 GMT</pubDate>
    <dc:creator>ShemSargent</dc:creator>
    <dc:date>2025-02-13T15:22:46Z</dc:date>
    <item>
      <title>Unit 42 Palo Alto  integration with SIEM particularly ?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/unit-42-palo-alto-integration-with-siem-particularly/m-p/584679#M6573</link>
      <description>&lt;P&gt;How can we integrate Unit 42 Palo Alto with SIEM particularly Microsoft Sentinel?&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Shashank&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 20:41:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/unit-42-palo-alto-integration-with-siem-particularly/m-p/584679#M6573</guid>
      <dc:creator>Shashanksinha</dc:creator>
      <dc:date>2024-04-23T20:41:21Z</dc:date>
    </item>
    <item>
      <title>Re: Unit 42 Palo Alto  integration with SIEM particularly ?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/unit-42-palo-alto-integration-with-siem-particularly/m-p/585075#M6606</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/203123"&gt;@Shashanksinha&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for reaching out on LiveCommunity!&lt;/P&gt;
&lt;P&gt;Can you please confirm what is your requirement? Because unit 42 is a threat research and incident response team. To know about the unit 42 services please reach out to your sales/account representative.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Apr 2024 15:04:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/unit-42-palo-alto-integration-with-siem-particularly/m-p/585075#M6606</guid>
      <dc:creator>nsinghvirk</dc:creator>
      <dc:date>2024-04-26T15:04:34Z</dc:date>
    </item>
    <item>
      <title>Re: Unit 42 Palo Alto  integration with SIEM particularly ?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/unit-42-palo-alto-integration-with-siem-particularly/m-p/1220379#M7879</link>
      <description>&lt;P&gt;Navigate to&amp;nbsp;&lt;A href="https://stix2.unit42.org" target="_blank"&gt;https://stix2.unit42.org&lt;/A&gt;&lt;SPAN data-ogsc="black" data-ogsb="white"&gt;&lt;A id="x_m_7801028442992494659OWAddd46645-2bff-aad0-c026-fccd31dd582d" title="https://urldefense.proofpoint.com/v2/url?u=https-3A__stix2.unit42.org_taxii_&amp;amp;d=DwMFaQ&amp;amp;c=V9IgWpI5PvzTw83UyHGVSoW3Uc1MFWe5J8PTfkrzVSo&amp;amp;r=JfdIyW7mPPBnkEtE1RpS0eUbppbccKCUzvE_QEp8-dg&amp;amp;m=rSVJxu1MPv0cIvn0pDshRxXP92qRk6QDNi_RbgT4JqM97ps-5YNPnWuf1vmj6Txa&amp;amp;s=3aN2l-5iFw-2gF5C8L37wVqEbr8SzsOtCSSw3c97ezU&amp;amp;e=" href="https://urldefense.proofpoint.com/v2/url?u=https-3A__stix2.unit42.org_taxii_&amp;amp;d=DwMFaQ&amp;amp;c=V9IgWpI5PvzTw83UyHGVSoW3Uc1MFWe5J8PTfkrzVSo&amp;amp;r=JfdIyW7mPPBnkEtE1RpS0eUbppbccKCUzvE_QEp8-dg&amp;amp;m=rSVJxu1MPv0cIvn0pDshRxXP92qRk6QDNi_RbgT4JqM97ps-5YNPnWuf1vmj6Txa&amp;amp;s=3aN2l-5iFw-2gF5C8L37wVqEbr8SzsOtCSSw3c97ezU&amp;amp;e=" data-auth="NotApplicable" data-linkindex="3" data-ogsc="" data-ogsb="white" target="_blank"&gt;&lt;/A&gt;. Create an account with email address (username) and password. (I created an API key, but I'm not sure that's necessary. It doesn't get used to authenticate from Sentinel.) Note the following details:&lt;/SPAN&gt;&lt;/P&gt;
&lt;TABLE id="x_m_7801028442992494659x_table_0" data-ogsb="white"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TH data-ogsb="rgb(88, 96, 106)"&gt;
&lt;DIV data-ogsc="black"&gt;&lt;SPAN&gt;Description&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/TH&gt;
&lt;TH data-ogsb="rgb(88, 96, 106)"&gt;
&lt;DIV data-ogsc="black"&gt;&lt;SPAN&gt;TAXII Discovery Service URL&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/TH&gt;
&lt;TH data-ogsb="rgb(88, 96, 106)"&gt;
&lt;DIV data-ogsc="black"&gt;&lt;SPAN&gt;TAXII API root&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/TH&gt;
&lt;TH data-ogsb="rgb(88, 96, 106)"&gt;
&lt;DIV data-ogsc="black"&gt;&lt;SPAN&gt;TAXII Collection ID&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/TH&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;DIV data-ogsc="black"&gt;Unit 42 Adversary Playbooks&lt;/DIV&gt;
&lt;/TD&gt;
&lt;TD&gt;&lt;A href="https://stix2.unit42.org/taxii/" target="_blank"&gt;https://stix2.unit42.org/taxii/&lt;/A&gt;&lt;/TD&gt;
&lt;TD&gt;
&lt;DIV data-ogsc="black"&gt;playbooks&lt;/DIV&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;DIV data-ogsc="black"&gt;[playbooks GUID]&lt;/DIV&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;DIV data-ogsc="black"&gt;Unit 42 Reports&lt;/DIV&gt;
&lt;/TD&gt;
&lt;TD&gt;&lt;A href="https://stix2.unit42.org/taxii/" target="_blank"&gt;https://stix2.unit42.org/taxii/&lt;/A&gt;&lt;/TD&gt;
&lt;TD&gt;
&lt;DIV data-ogsc="black"&gt;reports&lt;/DIV&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;DIV data-ogsc="black"&gt;[reports GUID]&lt;/DIV&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;DIV data-ogsc="black" data-ogsb="white"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV data-ogsc="black" data-ogsb="white"&gt;Navigate to&amp;nbsp;&lt;A href="https://stix2.unit42.org/taxii/" target="_blank"&gt;https://stix2.unit42.org/taxii/&lt;/A&gt;&amp;nbsp;and authenticate with the same username and password. Observe the api_roots in the JSON response:&lt;/DIV&gt;
&lt;DIV data-ogsc="black" data-ogsb="white"&gt;
&lt;BLOCKQUOTE&gt;
&lt;DIV data-ogsc="black"&gt;{ &amp;nbsp;"api_roots": [ &amp;nbsp; &amp;nbsp;"&lt;A href="https://stix2.unit42.org/playbooks/" target="_blank"&gt;https://stix2.unit42.org/playbooks/&lt;/A&gt;", &amp;nbsp; &amp;nbsp;"&lt;A href="https://stix2.unit42.org/reports/" target="_blank"&gt;https://stix2.unit42.org/reports/&lt;/A&gt;" &amp;nbsp;], &amp;nbsp;"contact": "&lt;A href="https://unit42.paloaltonetworks.com/" target="_blank"&gt;https://unit42.paloaltonetworks.com/&lt;/A&gt;", &amp;nbsp;"default": "&lt;A href="https://stix2.unit42.org/playbooks/" target="_blank"&gt;https://stix2.unit42.org/playbooks/&lt;/A&gt;", &amp;nbsp;"description": "Indicators from Palo Alto Networks Unit 42", &amp;nbsp;"host": "&lt;A href="https://stix2.unit42.org/" target="_blank"&gt;https://stix2.unit42.org/&lt;/A&gt;", &amp;nbsp;"title": "Unit 42 TAXII 2.0 Server" }&lt;/DIV&gt;
&lt;/BLOCKQUOTE&gt;
&lt;/DIV&gt;
&lt;DIV data-ogsc="black" data-ogsb="white"&gt;In Microsoft Sentinel, ensure the Threat Intelligence solution is enabled. Ensure the&amp;nbsp;Threat intelligence - TAXII connector is installed and open its connector page. Configure two TAXII servers with the following information:&lt;/DIV&gt;
&lt;DIV data-ogsc="black" data-ogsb="white"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV data-ogsc="black" data-ogsb="white"&gt;Friendly name (for server):&amp;nbsp;&lt;SPAN&gt;Unit42Reports&lt;/SPAN&gt;&lt;BR /&gt;API root URL:&amp;nbsp;&lt;A href="https://stix2.unit42.org/reports/" target="_blank"&gt;https://stix2.unit42.org/reports/&lt;/A&gt;&lt;BR /&gt;Collection ID: [reports GUID]&lt;BR /&gt;Username: [Unit 42 account username]&lt;BR /&gt;Password: [Unit 42 account password]&lt;BR /&gt;Import indicators: [choose best option for your context]&lt;BR /&gt;Polling frequency: [choose best option for your context]&amp;nbsp;&lt;/DIV&gt;
&lt;DIV data-ogsc="black" data-ogsb="white"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV data-ogsc="black" data-ogsb="white"&gt;
&lt;DIV data-ogsc="black" data-ogsb="white"&gt;Friendly name (for server): &lt;SPAN&gt;Unit42AdversaryPlaybooks&lt;/SPAN&gt;&lt;BR /&gt;API root URL:&amp;nbsp;&lt;A href="https://stix2.unit42.org/playbooks/" target="_blank"&gt;https://stix2.unit42.org/playbooks/&lt;/A&gt;&lt;BR /&gt;Collection ID: [playbooks GUID]&lt;BR /&gt;Username: [Unit 42 account username]&lt;BR /&gt;Password: [Unit 42 account password]&lt;BR /&gt;Import indicators: [choose best option for your context]&lt;BR /&gt;Polling frequency: [choose best option for your context]&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Thu, 13 Feb 2025 15:22:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/unit-42-palo-alto-integration-with-siem-particularly/m-p/1220379#M7879</guid>
      <dc:creator>ShemSargent</dc:creator>
      <dc:date>2025-02-13T15:22:46Z</dc:date>
    </item>
  </channel>
</rss>

