<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Help with feeds in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/help-with-feeds/m-p/577347#M3072</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/307134"&gt;@tlmarques&lt;/a&gt;, I would first check out the free feeds and free enrichers content packs in the XSOAR marketplace. These provide a large list of free feeds and enrichment integrations that can be used to help determine whether a domain is malicious or not. You can also leverage the Unit42 ATOMs feed as well. Overall I would not rely on a single feed or enrichment source to determine if an indicator is malicious or not. Try to enrich the URLs and domains against a few different enrichment sources to see what the verdict is. Some good enrichment sources for domains: VirusTotal, whois, Ipinfo. Combine those enrichment sources with feeds such as Unit42 ATOMs, SpamHaus, OpenPhish and this can help you to determine if an URL or Domain is malicious or not.&lt;/P&gt;</description>
    <pubDate>Thu, 15 Feb 2024 15:09:59 GMT</pubDate>
    <dc:creator>elmitchell</dc:creator>
    <dc:date>2024-02-15T15:09:59Z</dc:date>
    <item>
      <title>Help with feeds</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/help-with-feeds/m-p/575186#M3028</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hello, I need your help. I need feeds for domain classification and another feed for phishing, to determine whether domains have been compromised or not. What do you recommend for &lt;LI-PRODUCT title="Cortex XSOAR" id="Cortex_XSOAR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;#&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jan 2024 23:50:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/help-with-feeds/m-p/575186#M3028</guid>
      <dc:creator>tlmarques</dc:creator>
      <dc:date>2024-01-31T23:50:15Z</dc:date>
    </item>
    <item>
      <title>Re: Help with feeds</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/help-with-feeds/m-p/577347#M3072</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/307134"&gt;@tlmarques&lt;/a&gt;, I would first check out the free feeds and free enrichers content packs in the XSOAR marketplace. These provide a large list of free feeds and enrichment integrations that can be used to help determine whether a domain is malicious or not. You can also leverage the Unit42 ATOMs feed as well. Overall I would not rely on a single feed or enrichment source to determine if an indicator is malicious or not. Try to enrich the URLs and domains against a few different enrichment sources to see what the verdict is. Some good enrichment sources for domains: VirusTotal, whois, Ipinfo. Combine those enrichment sources with feeds such as Unit42 ATOMs, SpamHaus, OpenPhish and this can help you to determine if an URL or Domain is malicious or not.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Feb 2024 15:09:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/help-with-feeds/m-p/577347#M3072</guid>
      <dc:creator>elmitchell</dc:creator>
      <dc:date>2024-02-15T15:09:59Z</dc:date>
    </item>
  </channel>
</rss>

