<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Adding threat feeds to NGFW 850 - is there such a feature? in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/adding-threat-feeds-to-ngfw-850-is-there-such-a-feature/m-p/418129#M130</link>
    <description>&lt;P&gt;MISP can produce a text formatted file. I would like to know if in the firewall dashboard itself has a feature that I can define the threat source feed?&lt;/P&gt;</description>
    <pubDate>Fri, 09 Jul 2021 14:42:22 GMT</pubDate>
    <dc:creator>orlandoc</dc:creator>
    <dc:date>2021-07-09T14:42:22Z</dc:date>
    <item>
      <title>Adding threat feeds to NGFW 850 - is there such a feature?</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/adding-threat-feeds-to-ngfw-850-is-there-such-a-feature/m-p/415630#M126</link>
      <description>&lt;P&gt;Greetings,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;New to Palo Alto Firewall 850. I am wondering if this firewall has a feature that can ingest threat feeds from MISP.&lt;/P&gt;
&lt;P&gt;Please advise.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jun 2021 15:23:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/adding-threat-feeds-to-ngfw-850-is-there-such-a-feature/m-p/415630#M126</guid>
      <dc:creator>orlandoc</dc:creator>
      <dc:date>2021-06-28T15:23:43Z</dc:date>
    </item>
    <item>
      <title>Re: Adding threat feeds to NGFW 850 - is there such a feature?</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/adding-threat-feeds-to-ngfw-850-is-there-such-a-feature/m-p/415998#M127</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;While I have not done this, check out MindMeld:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/minemeld/ct-p/MineMeld" target="_blank"&gt;https://live.paloaltonetworks.com/t5/minemeld/ct-p/MineMeld&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It might work for you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jun 2021 16:44:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/adding-threat-feeds-to-ngfw-850-is-there-such-a-feature/m-p/415998#M127</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2021-06-29T16:44:34Z</dc:date>
    </item>
    <item>
      <title>Re: Adding threat feeds to NGFW 850 - is there such a feature?</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/adding-threat-feeds-to-ngfw-850-is-there-such-a-feature/m-p/416038#M128</link>
      <description>&lt;P&gt;The preferred way is to leverage External Dynamic List (EDLs)&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/policy/use-an-external-dynamic-list-in-policy/external-dynamic-list.html" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/policy/use-an-external-dynamic-list-in-policy/external-dynamic-list.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If the threat feeds from the MSP are formatted in a text file, there is a high probability one could just ingest them without using MindMeld (as OtakarKlier stated), but MindMeld will assist in normalizing and removing duplicates IOCs from various threat feeds. Also Cortex XSOAR also has the ability process IoC and create EDLs as well with their Threat Intel Management Module.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://www.paloaltonetworks.com/cortex/threat-intel-management" target="_blank"&gt;https://www.paloaltonetworks.com/cortex/threat-intel-management&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this Helps.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jun 2021 17:54:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/adding-threat-feeds-to-ngfw-850-is-there-such-a-feature/m-p/416038#M128</guid>
      <dc:creator>jhurtt</dc:creator>
      <dc:date>2021-06-29T17:54:41Z</dc:date>
    </item>
    <item>
      <title>Re: Adding threat feeds to NGFW 850 - is there such a feature?</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/adding-threat-feeds-to-ngfw-850-is-there-such-a-feature/m-p/416040#M129</link>
      <description>&lt;P&gt;Minemeld can mine that data and create EDLs, among others. There is also the product "Autofocus", but that may be getting ingested into Cortex soon.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jun 2021 17:56:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/adding-threat-feeds-to-ngfw-850-is-there-such-a-feature/m-p/416040#M129</guid>
      <dc:creator>LAYER_8</dc:creator>
      <dc:date>2021-06-29T17:56:16Z</dc:date>
    </item>
    <item>
      <title>Re: Adding threat feeds to NGFW 850 - is there such a feature?</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/adding-threat-feeds-to-ngfw-850-is-there-such-a-feature/m-p/418129#M130</link>
      <description>&lt;P&gt;MISP can produce a text formatted file. I would like to know if in the firewall dashboard itself has a feature that I can define the threat source feed?&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jul 2021 14:42:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/adding-threat-feeds-to-ngfw-850-is-there-such-a-feature/m-p/418129#M130</guid>
      <dc:creator>orlandoc</dc:creator>
      <dc:date>2021-07-09T14:42:22Z</dc:date>
    </item>
    <item>
      <title>Re: Adding threat feeds to NGFW 850 - is there such a feature?</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/adding-threat-feeds-to-ngfw-850-is-there-such-a-feature/m-p/418258#M131</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;It depends, if its an IP address or domain, then yes. But not like a SNORT rule.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jul 2021 17:18:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/adding-threat-feeds-to-ngfw-850-is-there-such-a-feature/m-p/418258#M131</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2021-07-09T17:18:34Z</dc:date>
    </item>
  </channel>
</rss>

