<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Using MineMeld with MISP in Automation/API Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/using-minemeld-with-misp/m-p/293210#M2058</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;First, thanks for your help.&lt;/P&gt;&lt;P&gt;OK I solved the issue.&lt;/P&gt;&lt;P&gt;The API key was not correct...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HA&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 17 Oct 2019 07:07:43 GMT</pubDate>
    <dc:creator>slp-security</dc:creator>
    <dc:date>2019-10-17T07:07:43Z</dc:date>
    <item>
      <title>Using MineMeld with MISP</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/using-minemeld-with-misp/m-p/230649#M1778</link>
      <description>&lt;P&gt;How can I pull the IOCs from MISP to MinMeld Plattform ?&lt;/P&gt;&lt;P&gt;Exist any extension to get the IOCs from MISP ?&lt;/P&gt;</description>
      <pubDate>Thu, 13 Sep 2018 03:25:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/using-minemeld-with-misp/m-p/230649#M1778</guid>
      <dc:creator>vhgambit</dc:creator>
      <dc:date>2018-09-13T03:25:12Z</dc:date>
    </item>
    <item>
      <title>Re: Using MineMeld with MISP</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/using-minemeld-with-misp/m-p/247398#M1852</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/66450"&gt;@vhgambit&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;try:&lt;/P&gt;&lt;P&gt;in SYSTEM &amp;gt; EXTENSIONS install the extension using &lt;EM&gt;git&lt;/EM&gt; button (&lt;A href="https://github.com/PaloAltoNetworks/minemeld-misp.git" target="_blank"&gt;https://github.com/PaloAltoNetworks/minemeld-misp.git&lt;/A&gt;)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;more details in: &lt;A href="https://github.com/PaloAltoNetworks/minemeld-misp" target="_blank"&gt;https://github.com/PaloAltoNetworks/minemeld-misp&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jan 2019 17:59:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/using-minemeld-with-misp/m-p/247398#M1852</guid>
      <dc:creator>TiagoSantos84</dc:creator>
      <dc:date>2019-01-24T17:59:17Z</dc:date>
    </item>
    <item>
      <title>Re: Using MineMeld with MISP</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/using-minemeld-with-misp/m-p/254735#M1882</link>
      <description>&lt;P&gt;Excellent, Tks a Lot&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/89099"&gt;@TiagoSantos84&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/66450"&gt;@vhgambit&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;try:&lt;/P&gt;&lt;P&gt;in SYSTEM &amp;gt; EXTENSIONS install the extension using &lt;EM&gt;git&lt;/EM&gt; button (&lt;A href="https://github.com/PaloAltoNetworks/minemeld-misp.git" target="_blank" rel="noopener"&gt;https://github.com/PaloAltoNetworks/minemeld-misp.git&lt;/A&gt;)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;more details in: &lt;A href="https://github.com/PaloAltoNetworks/minemeld-misp" target="_blank" rel="noopener"&gt;https://github.com/PaloAltoNetworks/minemeld-misp&lt;/A&gt;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2019 19:39:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/using-minemeld-with-misp/m-p/254735#M1882</guid>
      <dc:creator>vhgambit</dc:creator>
      <dc:date>2019-03-22T19:39:22Z</dc:date>
    </item>
    <item>
      <title>Re: Using MineMeld with MISP</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/using-minemeld-with-misp/m-p/293146#M2055</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm trying to integrate Minemeld with MISP.&lt;/P&gt;&lt;P&gt;I followed&amp;nbsp;&lt;A href="https://github.com/PaloAltoNetworks/minemeld-misp" target="_blank"&gt;https://github.com/PaloAltoNetworks/minemeld-misp&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Which&amp;nbsp;&lt;SPAN class="pl-c"&gt;URL of MISP (public)&amp;nbsp;&lt;/SPAN&gt;do I need to provide on the Prototype parameter ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HA&lt;/P&gt;</description>
      <pubDate>Wed, 16 Oct 2019 14:14:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/using-minemeld-with-misp/m-p/293146#M2055</guid>
      <dc:creator>slp-security</dc:creator>
      <dc:date>2019-10-16T14:14:48Z</dc:date>
    </item>
    <item>
      <title>Re: Using MineMeld with MISP</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/using-minemeld-with-misp/m-p/293149#M2056</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/105567"&gt;@slp-security&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't know if I understand your question, but you need to use your MISP url.&lt;/P&gt;&lt;DIV class="highlight highlight-source-yaml"&gt;&lt;PRE&gt;&lt;SPAN class="pl-c"&gt;Prototype parameters&lt;BR /&gt;# source name, to identify the origin of the indicators inside MineMeld&lt;/SPAN&gt;
&lt;SPAN class="pl-ent"&gt;source_name&lt;/SPAN&gt;: &lt;SPAN class="pl-s"&gt;misp.test&lt;/SPAN&gt;
&lt;SPAN class="pl-c"&gt;# URL of MISP&lt;/SPAN&gt;
&lt;SPAN class="pl-ent"&gt;url&lt;/SPAN&gt;: &lt;SPAN class="pl-s"&gt;https://misp.example.co&lt;/SPAN&gt;&lt;/PRE&gt;&lt;/DIV&gt;&lt;P&gt;Please be more specific.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;Tiago&lt;/P&gt;</description>
      <pubDate>Wed, 16 Oct 2019 14:34:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/using-minemeld-with-misp/m-p/293149#M2056</guid>
      <dc:creator>TiagoSantos84</dc:creator>
      <dc:date>2019-10-16T14:34:13Z</dc:date>
    </item>
    <item>
      <title>Re: Using MineMeld with MISP</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/using-minemeld-with-misp/m-p/293210#M2058</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;First, thanks for your help.&lt;/P&gt;&lt;P&gt;OK I solved the issue.&lt;/P&gt;&lt;P&gt;The API key was not correct...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HA&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Oct 2019 07:07:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/using-minemeld-with-misp/m-p/293210#M2058</guid>
      <dc:creator>slp-security</dc:creator>
      <dc:date>2019-10-17T07:07:43Z</dc:date>
    </item>
    <item>
      <title>Re: Using MineMeld with MISP</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/using-minemeld-with-misp/m-p/334870#M2386</link>
      <description>&lt;P&gt;Have you ever had this issue ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;- i clone this prototype as a new node :&amp;nbsp;misp.anyEvent&lt;/P&gt;&lt;P&gt;-&amp;nbsp;added the url and the API key from the GUI&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do i missed something ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="papham_1-1592941077366.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26364i14592FB0E580DAD8/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="papham_1-1592941077366.png" alt="papham_1-1592941077366.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="papham_2-1592941210161.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26365i583923B19DDD3713/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="papham_2-1592941210161.png" alt="papham_2-1592941210161.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jun 2020 19:44:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/using-minemeld-with-misp/m-p/334870#M2386</guid>
      <dc:creator>papham</dc:creator>
      <dc:date>2020-06-23T19:44:21Z</dc:date>
    </item>
    <item>
      <title>Re: Using MineMeld with MISP</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/using-minemeld-with-misp/m-p/334877#M2387</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/146783"&gt;@papham&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Try to confirm your auth key..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Certificates installed on misp? Do you have a self signed certificate?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But it should be straight forward.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jun 2020 20:25:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/using-minemeld-with-misp/m-p/334877#M2387</guid>
      <dc:creator>TiagoSantos84</dc:creator>
      <dc:date>2020-06-23T20:25:13Z</dc:date>
    </item>
    <item>
      <title>Re: Using MineMeld with MISP</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/using-minemeld-with-misp/m-p/336827#M2397</link>
      <description>&lt;P&gt;My MISP miner seems to work&amp;nbsp;OK, i'm&amp;nbsp;using the IDS check box as the filter to&amp;nbsp;block IoC's - How do I unblock an&amp;nbsp;IoC,&amp;nbsp;is it as simple as unchecking the IDS box in MISP, will that update the EDL?&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jul 2020 09:15:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/using-minemeld-with-misp/m-p/336827#M2397</guid>
      <dc:creator>Tony101</dc:creator>
      <dc:date>2020-07-07T09:15:18Z</dc:date>
    </item>
    <item>
      <title>Re: Using MineMeld with MISP</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/using-minemeld-with-misp/m-p/336832#M2398</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/148127"&gt;@Tony101&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It really depends on how the receiver deal with data. There is some platforms that will update the list of IoCs after some amount of time. On the other hand you can try to disable IDS flag on the MISP and delete the IoC on the destination that already receive the IoC as black list.&lt;/P&gt;&lt;P&gt;However, you just need to remove IDS flag if you don't have the enforcewarninglist flag active on the query and if you don't have any warninglist feed active.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please take a look on this:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;A href="https://github.com/MISP/misp-warninglists" target="_blank" rel="noopener"&gt;https://github.com/MISP/misp-warninglists&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;like this example (credits from Dev Team MISP):&lt;PRE&gt;https://your.misp/attributes/restSearch/returnFormat:suricata/publish_timestamp:15d/enforceWarninglist:1&lt;/PRE&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Hope that you can manage it. It's really hard to deal with false positives!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jul 2020 10:17:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/using-minemeld-with-misp/m-p/336832#M2398</guid>
      <dc:creator>TiagoSantos84</dc:creator>
      <dc:date>2020-07-07T10:17:10Z</dc:date>
    </item>
    <item>
      <title>Re: Using MineMeld with MISP</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/using-minemeld-with-misp/m-p/358481#M2482</link>
      <description>&lt;P&gt;Hi thanks for the previous answer, it was really helpful.. I have another question re the output FEED BASE URL:&lt;/P&gt;&lt;P&gt;appending ?v=mwg&amp;amp;t=regex to the feed base url gives me the format i require e.g..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;type=regex&lt;BR /&gt;"&lt;A href="http://badsite.biz/malware.html" target="_blank"&gt;hxxp://badsite[.]biz/malware.html&lt;/A&gt;" "comment"&lt;/PRE&gt;&lt;P&gt;But what i really want to achieve is an * wildcard at the end of the string e.g.&lt;/P&gt;&lt;P&gt;"&lt;A href="http://badsite.biz/malware.html" target="_blank"&gt;hxxp://badsite[.]biz/malware.html*&lt;/A&gt;" "comment"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas if this is do-able?&lt;/P&gt;</description>
      <pubDate>Fri, 23 Oct 2020 14:19:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/using-minemeld-with-misp/m-p/358481#M2482</guid>
      <dc:creator>Tony101</dc:creator>
      <dc:date>2020-10-23T14:19:51Z</dc:date>
    </item>
    <item>
      <title>Re: Using MineMeld with MISP</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/using-minemeld-with-misp/m-p/363616#M2498</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;we have recently installed MineMeld on our Linux server and after adding the MISP extension on MineMeld, I don't understand what it means by add your MISP URL. Is this URL found from MISP website or is it a URL we get after installing MISP. Between we haven't installed MISP as well. Is it required for the miner to work ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Another question I have is regarding the dynamic lists on MISP website. Do we add them with MISP miner or regular miners can pull them too?&lt;/P&gt;&lt;P&gt;I'm very new to MineMeld and I don't quite understand how to configure nodes. So I would appreciate if you could provide me a sample of a configuration for MISP feeds.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Nov 2020 17:51:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/using-minemeld-with-misp/m-p/363616#M2498</guid>
      <dc:creator>Negin-Amou</dc:creator>
      <dc:date>2020-11-17T17:51:30Z</dc:date>
    </item>
    <item>
      <title>Re: Using MineMeld with MISP</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/using-minemeld-with-misp/m-p/363624#M2499</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;MISP url is the address of you MISP instance. So you need to install it, create a sync user and put the key of that user in the miner.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please follow the links provided in previous posts.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;Tiago&lt;/P&gt;</description>
      <pubDate>Tue, 17 Nov 2020 18:17:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/using-minemeld-with-misp/m-p/363624#M2499</guid>
      <dc:creator>TiagoSantos84</dc:creator>
      <dc:date>2020-11-17T18:17:25Z</dc:date>
    </item>
    <item>
      <title>Re: Using MineMeld with MISP</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/using-minemeld-with-misp/m-p/428124#M2766</link>
      <description>&lt;P&gt;Hi guys, but&lt;/P&gt;&lt;PRE&gt;&lt;SPAN class="pl-c"&gt;source name, to identify the origin of the indicators inside MineMeld&lt;/SPAN&gt;&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;Source name is generic? Can i choose every name?&lt;/P&gt;</description>
      <pubDate>Fri, 20 Aug 2021 15:57:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/using-minemeld-with-misp/m-p/428124#M2766</guid>
      <dc:creator>MScoppettuolo</dc:creator>
      <dc:date>2021-08-20T15:57:22Z</dc:date>
    </item>
  </channel>
</rss>

