Welcome! You’ve found a Live Community first look article focused on PAN-OS 8.0. This article highlights a cool new capability or feature, personally selected by one of our very own Live Community engineers. It’s just the start, though. If you’d like to learn more about this topic or PAN-OS 8.0 in-general, you’ll also want to check out our world-class Technical Documentation.
For those of you who are unfamiliar with AutoFocus. Simply put, the service allows you to prioritize advanced, targeted cyber attacks and will help security teams to take a more strategic approach to secure their organizations.
Sounds pretty awesome, right? So how could we possibly make this better?
Until today, MineMeld existed as an independent solution, but now we've integrated the awesomeness of MineMeld into AutoFocus, removing the need to deploy a separate host for it in your environment.
For those who don't know MineMeld, it's a threat intelligence processing framework that can be used to collect, aggregate and generate IOCs and make them available for consumption. It is a Palo Alto Networks open source application available on GitHub and support is provided via the Live Community MineMeld Forum by Palo Alto Networks experts and independent contributors.
For a general overview of MineMeld ,you can go here.
If you are familiar with AutoFocus, you will notice a couple of new menu items on the left side of the portal page:
The new items are Indicators, Reports, Apps & MineMeld (this last one will only be visible if the service is started).
For guidance on how to use MineMeld check out this Live Community section dedicated to MineMeld.
What is truly awesome here is that you can easily create a new MineMeld miner based on selected criteria using the MineMeld button. This will automatically navigate you to the "Add AutoFocus Artifacs Miner" and will have the query already preconfigured for you :
The indicators are managed through the MineMeld application. They will be highlighted throughout AutoFocus with the icon. This gives you high confidence that the sample is indeed bad because it is confirmed by 2 different datasets (AutoFocus & MineMeld).
Also new is the Indicators tab in Search result. This page will give you a consolidated view of all the indicators from the current Samples page. Here also the icon will indicate that there is a correlation found between the Indicator store and the samples found within the search.
Similar to the Indicator store, using the MineMeld button, you can easily create a new miner with your matching conditions already preconfigured. Clicking the MineMeld button will navigate you to the "Add AutoFocus Samples Miner".
Below are just a few of many use cases for which you might find this useful: