<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Zero indicators in inboundfeed in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/zero-indicators-in-inboundfeed/m-p/195181#M97611</link>
    <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/6710"&gt;@xhoms&lt;/a&gt;, That helped.&lt;/P&gt;&lt;P&gt;One more thing, i was able to follow this &lt;A href="https://live.paloaltonetworks.com/t5/MineMeld-Articles/Customizing-Prototypes/ta-p/72045" target="_self"&gt;customizing minemeld article&lt;/A&gt; to copy and create a new miner in cli. But i also saw another article which shows a way of doing it in &lt;A href="https://live.paloaltonetworks.com/t5/MineMeld-Discussions/Talos-Blacklist/m-p/190671#M1737" target="_self"&gt;GUI&lt;/A&gt;,&amp;nbsp;would you know how.&lt;/P&gt;</description>
    <pubDate>Mon, 15 Jan 2018 17:14:32 GMT</pubDate>
    <dc:creator>raji_toor</dc:creator>
    <dc:date>2018-01-15T17:14:32Z</dc:date>
    <item>
      <title>Zero indicators in inboundfeed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zero-indicators-in-inboundfeed/m-p/194991#M97609</link>
      <description>&lt;P&gt;I am trying out minemeld and &lt;SPAN&gt;I started by adding miner (zeustracker.badips) and&lt;/SPAN&gt;&amp;nbsp;removing the default dshield and spam nodes. Before removal inbound feeds were showing subnet ranges/indicators.&amp;nbsp;After removal there is not a single ip. processor shows RX count and PROCESSED count but output is all zero. Am i doing something wrong?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2018 18:56:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zero-indicators-in-inboundfeed/m-p/194991#M97609</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2018-01-12T18:56:59Z</dc:date>
    </item>
    <item>
      <title>Re: Zero indicators in inboundfeed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zero-indicators-in-inboundfeed/m-p/195045#M97610</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/56221"&gt;@raji_toor&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you're facing an 'inbound' vs 'outbount' situation. Some threat intel feeds provide you with an attribute attached to the indicators meant to describe whether you should not connect to these IP's (outbound) or you should not accept connections from these IP's (inbound).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The dafault config include miners that attach the 'inbound' attribute to the indicators and an aggregator that enforces it. The following capture shows you the aggregator prototype: it accepts indicators of type IPv4 with attribute 'inbound' or 'null' and discards everything else.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="2018-01-13_09-37-34.png" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/13215iD4A265DF08ED5E87/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="2018-01-13_09-37-34.png" alt="2018-01-13_09-37-34.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now take a look to the Zeus Bad IP Prototype.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="2018-01-13_09-40-32.png" style="width: 577px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/13216i376E3BAFB0028554/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2018-01-13_09-40-32.png" alt="2018-01-13_09-40-32.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As you can see, nodes based in this prototype will attach the outbound attribute to received indicators. And that will make the aggregator to discard them. If you take a look to the aggregator logs you'll find the discard action.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="2018-01-13_09-43-37.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/13217iA2E9D04584B73BB3/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2018-01-13_09-43-37.png" alt="2018-01-13_09-43-37.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You have many options:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Create a new prototype out of stdlib.aggregatorIPv4Inbound but removing the direction filter criteria (just accept type == 'IPv4')&lt;/LI&gt;
&lt;LI&gt;Just use the aggregator stdlib.aggregatorIPv4Generic that is, in fact, what you'll achieve following the previous suggestion.&lt;/LI&gt;
&lt;LI&gt;Create a new miner prototype out of zeustracker.badips but removing the direction attribute. That will make the indicators match because of the accep direction == 'null' filter action.&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Sat, 13 Jan 2018 08:51:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zero-indicators-in-inboundfeed/m-p/195045#M97610</guid>
      <dc:creator>xhoms</dc:creator>
      <dc:date>2018-01-13T08:51:15Z</dc:date>
    </item>
    <item>
      <title>Re: Zero indicators in inboundfeed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zero-indicators-in-inboundfeed/m-p/195181#M97611</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/6710"&gt;@xhoms&lt;/a&gt;, That helped.&lt;/P&gt;&lt;P&gt;One more thing, i was able to follow this &lt;A href="https://live.paloaltonetworks.com/t5/MineMeld-Articles/Customizing-Prototypes/ta-p/72045" target="_self"&gt;customizing minemeld article&lt;/A&gt; to copy and create a new miner in cli. But i also saw another article which shows a way of doing it in &lt;A href="https://live.paloaltonetworks.com/t5/MineMeld-Discussions/Talos-Blacklist/m-p/190671#M1737" target="_self"&gt;GUI&lt;/A&gt;,&amp;nbsp;would you know how.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jan 2018 17:14:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zero-indicators-in-inboundfeed/m-p/195181#M97611</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2018-01-15T17:14:32Z</dc:date>
    </item>
    <item>
      <title>Re: Zero indicators in inboundfeed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zero-indicators-in-inboundfeed/m-p/195183#M97612</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/56221"&gt;@raji_toor&lt;/a&gt;, follow examples like the Step 3 in the article &lt;A href="https://live.paloaltonetworks.com/t5/MineMeld-Articles/Using-MineMeld-to-generate-IP-lists-from-wildcards/ta-p/186213" target="_self"&gt;MineMeld-Articles/Using-MineMeld-to-generate-IP-lists-from-wildcards&lt;/A&gt; to discover how to create new prototypes using the WEB UI&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jan 2018 18:47:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zero-indicators-in-inboundfeed/m-p/195183#M97612</guid>
      <dc:creator>xhoms</dc:creator>
      <dc:date>2018-01-15T18:47:19Z</dc:date>
    </item>
  </channel>
</rss>

