<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Autofocus Mindmeld whitelist microsoft in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/autofocus-mindmeld-whitelist-microsoft/m-p/238214#M97342</link>
    <description>&lt;P&gt;I'm running into an issue where I can pull in indicators from autofocus by creating a minemeld miner, the only problem is that I am getting a lot of windows.com and microsoft.com domains in the list.&amp;nbsp; I've had the search from autofocus entered as malicious/grayware/phishing, but still the miner is pulling in microsoft domains and windowsupadate.com domains that I want to&amp;nbsp; ensure are always whitelisted.&amp;nbsp; I have whitelist local miners that i can manually add these to, but how do I *.windowsupdate.com or *.microsoft.com&amp;nbsp; these so I never see these in the list.&amp;nbsp; &amp;nbsp;These miners are useless to me if I can't more granularly control what is coming in on the list...&lt;/P&gt;</description>
    <pubDate>Thu, 01 Nov 2018 15:30:35 GMT</pubDate>
    <dc:creator>Sec101</dc:creator>
    <dc:date>2018-11-01T15:30:35Z</dc:date>
    <item>
      <title>Autofocus Mindmeld whitelist microsoft</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/autofocus-mindmeld-whitelist-microsoft/m-p/238214#M97342</link>
      <description>&lt;P&gt;I'm running into an issue where I can pull in indicators from autofocus by creating a minemeld miner, the only problem is that I am getting a lot of windows.com and microsoft.com domains in the list.&amp;nbsp; I've had the search from autofocus entered as malicious/grayware/phishing, but still the miner is pulling in microsoft domains and windowsupadate.com domains that I want to&amp;nbsp; ensure are always whitelisted.&amp;nbsp; I have whitelist local miners that i can manually add these to, but how do I *.windowsupdate.com or *.microsoft.com&amp;nbsp; these so I never see these in the list.&amp;nbsp; &amp;nbsp;These miners are useless to me if I can't more granularly control what is coming in on the list...&lt;/P&gt;</description>
      <pubDate>Thu, 01 Nov 2018 15:30:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/autofocus-mindmeld-whitelist-microsoft/m-p/238214#M97342</guid>
      <dc:creator>Sec101</dc:creator>
      <dc:date>2018-11-01T15:30:35Z</dc:date>
    </item>
    <item>
      <title>Re: Autofocus Mindmeld whitelist microsoft</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/autofocus-mindmeld-whitelist-microsoft/m-p/240562#M97343</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/59122"&gt;@Sec101&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;are you selecting only High Confidence indicators from AF? The microsoft.com, ... should all have low confidence.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Nov 2018 13:25:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/autofocus-mindmeld-whitelist-microsoft/m-p/240562#M97343</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2018-11-20T13:25:32Z</dc:date>
    </item>
    <item>
      <title>Re: Autofocus Mindmeld whitelist microsoft</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/autofocus-mindmeld-whitelist-microsoft/m-p/240599#M97344</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I think that was it.&amp;nbsp; Thank you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Found it on one of your other posts:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/MineMeld-Discussions/Confidence-level-in-logs/td-p/219849&amp;nbsp;" target="_blank"&gt;https://live.paloaltonetworks.com/t5/MineMeld-Discussions/Confidence-level-in-logs/td-p/219849&amp;nbsp;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I was using the below ouput:&lt;/P&gt;
&lt;P&gt;stdlib.feedRedWithValue&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Your saying that if I filter by output node, with confidence greater than 75 I should be good to go and not have to worry about these?&amp;nbsp; Do you suggest specifying a Wildfire verdict in the search, or is that something that AF takes care of with confidence levels?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Nov 2018 19:30:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/autofocus-mindmeld-whitelist-microsoft/m-p/240599#M97344</guid>
      <dc:creator>Sec101</dc:creator>
      <dc:date>2018-11-20T19:30:40Z</dc:date>
    </item>
    <item>
      <title>Re: Autofocus Mindmeld whitelist microsoft</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/autofocus-mindmeld-whitelist-microsoft/m-p/240652#M97346</link>
      <description>&lt;P&gt;I would specify it to avoid processing useless samples, but AF&amp;nbsp;also takes care of it in the IOC confidence level.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Nov 2018 22:54:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/autofocus-mindmeld-whitelist-microsoft/m-p/240652#M97346</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2018-11-20T22:54:28Z</dc:date>
    </item>
    <item>
      <title>Re: Autofocus Mindmeld whitelist microsoft</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/autofocus-mindmeld-whitelist-microsoft/m-p/240726#M97347</link>
      <description>&lt;P&gt;Thank you.&amp;nbsp; This is the perfect answer for this.&amp;nbsp; Hopefully this helps someone else out as well.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Nov 2018 14:42:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/autofocus-mindmeld-whitelist-microsoft/m-p/240726#M97347</guid>
      <dc:creator>Sec101</dc:creator>
      <dc:date>2018-11-21T14:42:08Z</dc:date>
    </item>
  </channel>
</rss>

