<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How do you setup FS-ISAC STIX/TAXII feeds to minemeld? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-do-you-setup-fs-isac-stix-taxii-feeds-to-minemeld/m-p/409912#M95261</link>
    <description>&lt;P&gt;I was following this thread here:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/minemeld-discussions/fs-isac-new-stix-taxii-feeds/td-p/334068" target="_blank"&gt;https://live.paloaltonetworks.com/t5/minemeld-discussions/fs-isac-new-stix-taxii-feeds/td-p/334068&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But nobody responded to my question so I'm starting a new thread hopefully to gain some visibility.&amp;nbsp; We've upped our membership with FS-ISAC which comes with an added annual fee, so being that we are paying for this service we want to get it to work with minemeld so we can have dynamic lists pushed into PA firewalls.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you look at the thread I posted above you can see some configuration guidance, however, a lot of the details are blurred out.&amp;nbsp; I have a quick reference guide from FS-ISAC and it shows 3 URL's for 3 different versions of TAXII.&lt;/P&gt;
&lt;P&gt;TAXII 1.1&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- Discovery Service&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- Collection Service&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- Poll Serivce&lt;/P&gt;
&lt;P&gt;TAXII 2.0&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- Discovery Service&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- Collection Service&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- Poll Serivce&lt;/P&gt;
&lt;P&gt;TAXII 2.1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- Discovery Service&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- Collection Service&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- Poll Serivce&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My first question is which URL(s) am I supposed to use?&amp;nbsp; Which version and which one (Discovery, Collection or poll)?&lt;/P&gt;
&lt;P&gt;Next on the second page they have whats called FS-ISAC STIX/TAXII Collections (as of August 4, 2020).&amp;nbsp; They have TAXII1.0 collection names in plain englisth, like automated-high-gw for example.&amp;nbsp; They also have a column for TAXII2.x Collection ID which looks more like a long GUID identifier than anything legible.&amp;nbsp; Finally the third column is a description.&lt;/P&gt;
&lt;P&gt;Am I supposed to pick one of these and put its Collection Name and / or ID somewhere?&amp;nbsp; How do you know which one to pick?&amp;nbsp; Something like curated-ragw says "Group packages containing analyst-created cyber threat intelligence with TLP values RED,AMBER,GREEN, and WHITE".&amp;nbsp; Would that be a good one?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Whatever I've tried I just get an error timed out in the last run column in minemeld.&amp;nbsp; I even waited a week for FS-ISAC to get our IP addresses in their ip whitelist.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Appreciate any help you have.&lt;/P&gt;</description>
    <pubDate>Fri, 28 May 2021 20:42:51 GMT</pubDate>
    <dc:creator>ksauer507</dc:creator>
    <dc:date>2021-05-28T20:42:51Z</dc:date>
    <item>
      <title>How do you setup FS-ISAC STIX/TAXII feeds to minemeld?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-do-you-setup-fs-isac-stix-taxii-feeds-to-minemeld/m-p/409912#M95261</link>
      <description>&lt;P&gt;I was following this thread here:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/minemeld-discussions/fs-isac-new-stix-taxii-feeds/td-p/334068" target="_blank"&gt;https://live.paloaltonetworks.com/t5/minemeld-discussions/fs-isac-new-stix-taxii-feeds/td-p/334068&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But nobody responded to my question so I'm starting a new thread hopefully to gain some visibility.&amp;nbsp; We've upped our membership with FS-ISAC which comes with an added annual fee, so being that we are paying for this service we want to get it to work with minemeld so we can have dynamic lists pushed into PA firewalls.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you look at the thread I posted above you can see some configuration guidance, however, a lot of the details are blurred out.&amp;nbsp; I have a quick reference guide from FS-ISAC and it shows 3 URL's for 3 different versions of TAXII.&lt;/P&gt;
&lt;P&gt;TAXII 1.1&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- Discovery Service&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- Collection Service&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- Poll Serivce&lt;/P&gt;
&lt;P&gt;TAXII 2.0&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- Discovery Service&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- Collection Service&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- Poll Serivce&lt;/P&gt;
&lt;P&gt;TAXII 2.1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- Discovery Service&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- Collection Service&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- Poll Serivce&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My first question is which URL(s) am I supposed to use?&amp;nbsp; Which version and which one (Discovery, Collection or poll)?&lt;/P&gt;
&lt;P&gt;Next on the second page they have whats called FS-ISAC STIX/TAXII Collections (as of August 4, 2020).&amp;nbsp; They have TAXII1.0 collection names in plain englisth, like automated-high-gw for example.&amp;nbsp; They also have a column for TAXII2.x Collection ID which looks more like a long GUID identifier than anything legible.&amp;nbsp; Finally the third column is a description.&lt;/P&gt;
&lt;P&gt;Am I supposed to pick one of these and put its Collection Name and / or ID somewhere?&amp;nbsp; How do you know which one to pick?&amp;nbsp; Something like curated-ragw says "Group packages containing analyst-created cyber threat intelligence with TLP values RED,AMBER,GREEN, and WHITE".&amp;nbsp; Would that be a good one?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Whatever I've tried I just get an error timed out in the last run column in minemeld.&amp;nbsp; I even waited a week for FS-ISAC to get our IP addresses in their ip whitelist.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Appreciate any help you have.&lt;/P&gt;</description>
      <pubDate>Fri, 28 May 2021 20:42:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-do-you-setup-fs-isac-stix-taxii-feeds-to-minemeld/m-p/409912#M95261</guid>
      <dc:creator>ksauer507</dc:creator>
      <dc:date>2021-05-28T20:42:51Z</dc:date>
    </item>
    <item>
      <title>Re: How do you setup FS-ISAC STIX/TAXII feeds to minemeld?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-do-you-setup-fs-isac-stix-taxii-feeds-to-minemeld/m-p/411914#M95262</link>
      <description>&lt;P&gt;Wow I must have stumped this forum, or maybe the start of summer everyone is out on vacation or something.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Jun 2021 20:20:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-do-you-setup-fs-isac-stix-taxii-feeds-to-minemeld/m-p/411914#M95262</guid>
      <dc:creator>ksauer507</dc:creator>
      <dc:date>2021-06-08T20:20:30Z</dc:date>
    </item>
    <item>
      <title>Re: How do you setup FS-ISAC STIX/TAXII feeds to minemeld?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-do-you-setup-fs-isac-stix-taxii-feeds-to-minemeld/m-p/470919#M103046</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/178800"&gt;@ksauer507&lt;/a&gt;&amp;nbsp;you should use the URL of TAXII 1.1 discovery service, and use the TAXII 1.1 collection names.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Mar 2022 14:46:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-do-you-setup-fs-isac-stix-taxii-feeds-to-minemeld/m-p/470919#M103046</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2022-03-07T14:46:39Z</dc:date>
    </item>
  </channel>
</rss>

