<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SWIFT ISAC TAXII Feed in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/swift-isac-taxii-feed/m-p/213108#M95431</link>
    <description>&lt;P&gt;Hi Salva,&lt;/P&gt;
&lt;P&gt;I haven't tested the SWIFT feed yet. If you are interested in working on this together, could you&amp;nbsp;send me an email at lmori@paloaltonetworks.com or a message over the pan-community Slack team?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 04 May 2018 08:27:49 GMT</pubDate>
    <dc:creator>lmori</dc:creator>
    <dc:date>2018-05-04T08:27:49Z</dc:date>
    <item>
      <title>SWIFT ISAC TAXII Feed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/swift-isac-taxii-feed/m-p/212034#M95430</link>
      <description>&lt;P&gt;Hi guys&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I’m’ just curious – SWIFT has offered recently for all members TAXII interface to poll IOCs via &amp;nbsp;&lt;A href="https://taxii.swift.com/taxii" target="_blank"&gt;https://taxii.swift.com/taxii&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Feed is not open for everybody – each member must request access to it individually, so it’s not easy to test it. Has anybody already tried it? My simple attempt to use “minemeld.ft.taxii.TaxiiClient” class to build own prototype failed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After defining username, password, discovery URL, collection - &amp;gt;I can only see the error message in nodes list.&lt;/P&gt;
&lt;P&gt;&amp;lt;urlopen error [Errno 0] _ssl.c:344: error:00000000:lib(0):func(0):reason(0)&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;SWIFT suggest to use Cabby Python library&lt;/P&gt;
&lt;P&gt;STIX version used is 1.2&lt;/P&gt;
&lt;P&gt;Any ideas suggestions, experience?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers&lt;/P&gt;
&lt;P&gt;Slava&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;P.S. MineMeld is a great tool!&lt;/P&gt;</description>
      <pubDate>Fri, 27 Apr 2018 13:15:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/swift-isac-taxii-feed/m-p/212034#M95430</guid>
      <dc:creator>Sberbank-IT</dc:creator>
      <dc:date>2018-04-27T13:15:54Z</dc:date>
    </item>
    <item>
      <title>Re: SWIFT ISAC TAXII Feed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/swift-isac-taxii-feed/m-p/213108#M95431</link>
      <description>&lt;P&gt;Hi Salva,&lt;/P&gt;
&lt;P&gt;I haven't tested the SWIFT feed yet. If you are interested in working on this together, could you&amp;nbsp;send me an email at lmori@paloaltonetworks.com or a message over the pan-community Slack team?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 May 2018 08:27:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/swift-isac-taxii-feed/m-p/213108#M95431</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2018-05-04T08:27:49Z</dc:date>
    </item>
    <item>
      <title>Re: SWIFT ISAC TAXII Feed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/swift-isac-taxii-feed/m-p/213676#M95432</link>
      <description>&lt;P&gt;Hi Guy,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any update?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am interested in pulling data from SWIFT too.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 May 2018 04:11:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/swift-isac-taxii-feed/m-p/213676#M95432</guid>
      <dc:creator>iThreatHunt</dc:creator>
      <dc:date>2018-05-09T04:11:38Z</dc:date>
    </item>
    <item>
      <title>Re: SWIFT ISAC TAXII Feed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/swift-isac-taxii-feed/m-p/214162#M95433</link>
      <description>&lt;P&gt;Hi all&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm playing now with Anomali STAXX Version 3.4 as TAXII client - hope to see this working first. I&amp;nbsp;hope, this is the easy way to start with.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Right now it looks like SWIFT has not defined all required permissions for tools using "Discovery" logic&lt;/P&gt;
&lt;P&gt;I have an open case with SWIFT, Case N:&amp;nbsp;&lt;SPAN&gt;11074471&lt;/SPAN&gt;&amp;nbsp;- if you need the reference. Investigation is in progress.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I will come back to MineMeld as soon as I see&amp;nbsp;&lt;SPAN&gt;STAXX working.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Vyacheslav&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 May 2018 12:03:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/swift-isac-taxii-feed/m-p/214162#M95433</guid>
      <dc:creator>Sberbank-IT</dc:creator>
      <dc:date>2018-05-14T12:03:03Z</dc:date>
    </item>
    <item>
      <title>Re: SWIFT ISAC TAXII Feed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/swift-isac-taxii-feed/m-p/217469#M95434</link>
      <description>&lt;P&gt;Hi Guys&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just a quick update from my side – feed still doesn’t work with basic Anomaly STAXX client configuration&lt;/P&gt;
&lt;P&gt;SWIFT and Anomaly working with joined efforts to find a solution here.&lt;/P&gt;
&lt;P&gt;As soon as I test it on our STAXX instance – we can continue with MineMeld configuration&lt;/P&gt;
&lt;P&gt;Cheers&lt;/P&gt;
&lt;P&gt;Vyacheslav&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jun 2018 06:56:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/swift-isac-taxii-feed/m-p/217469#M95434</guid>
      <dc:creator>Sberbank-IT</dc:creator>
      <dc:date>2018-06-12T06:56:25Z</dc:date>
    </item>
    <item>
      <title>Re: SWIFT ISAC TAXII Feed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/swift-isac-taxii-feed/m-p/223500#M95435</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just a quick update from my side. Even though the news is rather frustrating:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Anomali STAXX 3.4 still can’t get the feed.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;Minemeld report error: “SWIFT-ISAC does not support TAXII 1.1 messages binding (DATA_FEED)”&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It looks like SWIFT accept TAXII v2.0 only and both system struggle to support this protocol.&lt;/P&gt;
&lt;P&gt;Does anybody know anything about TAXII v2.0 support in MineMeld?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have a great, stable day&lt;/P&gt;
&lt;P&gt;Slava&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jul 2018 08:12:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/swift-isac-taxii-feed/m-p/223500#M95435</guid>
      <dc:creator>Sberbank-IT</dc:creator>
      <dc:date>2018-07-25T08:12:09Z</dc:date>
    </item>
    <item>
      <title>Re: SWIFT ISAC TAXII Feed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/swift-isac-taxii-feed/m-p/386409#M95436</link>
      <description>&lt;P&gt;If it' relevant for anybody - I have jests tested:&lt;/P&gt;
&lt;P&gt;- fresh Ubuntu 16 LTSB installation with all security patches&lt;/P&gt;
&lt;P&gt;- Minemeld&amp;nbsp;0.9.70&lt;/P&gt;
&lt;P&gt;- Downloaded new TAXII miner, following instructions from&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/minemeld-discussions/fs-isac-new-stix-taxii-feeds/td-p/334068" target="_blank"&gt;https://live.paloaltonetworks.com/t5/minemeld-discussions/fs-isac-new-stix-taxii-feeds/td-p/334068&lt;/A&gt;&amp;nbsp;(ver.&amp;nbsp;0.2a4 is fine)&lt;/P&gt;
&lt;P&gt;All works fine as I can see &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Good luck for everybody&lt;/P&gt;
&lt;P&gt;Slava&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Config of the SWIFT ISAC prototype:&lt;/P&gt;
&lt;P&gt;age_out:&lt;BR /&gt;default: null&lt;BR /&gt;interval: 3600&lt;BR /&gt;sudden_death: false&lt;BR /&gt;attributes:&lt;BR /&gt;confidence: 100&lt;BR /&gt;share_level: red&lt;BR /&gt;collection: SWIFT-ISAC&lt;BR /&gt;discovery_service: &lt;A href="https://taxii.swift.com/taxii/discovery" target="_blank"&gt;https://taxii.swift.com/taxii/discovery&lt;/A&gt;&lt;BR /&gt;initial_interval: 365d&lt;BR /&gt;password: your_pass&lt;BR /&gt;username: api_user_your_account&lt;BR /&gt;verify_cert: true&lt;/P&gt;</description>
      <pubDate>Wed, 17 Feb 2021 16:24:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/swift-isac-taxii-feed/m-p/386409#M95436</guid>
      <dc:creator>Sberbank-IT</dc:creator>
      <dc:date>2021-02-17T16:24:08Z</dc:date>
    </item>
  </channel>
</rss>

