MineMeld into Proofpoint TRAP

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

MineMeld into Proofpoint TRAP

L1 Bithead

I am trying to integrate MineMeld and Proofpoint TRAP. It should be relatively simple and feel I am overlooking something. 

The first step was easy. Create an output using stdlib.taxiiDataFeed. 

Because this is the community edition auth is turned off by default. (Leaving this off until things are working) 

In TRAP you have the following fields: 

URL: 
https://url.to.minemeld.com/taxii-discovery-service 

Feed: 
Unique_IP_taxiiDataFeed 

TAXII version: 
TAXII 1.x 

Confidence: 
USE STIX 

Poll Interval: 
Interval Here 

Require Auth: 
Not Checked (For Now) 

Select SSL Client Cert: 
None (For Now) 

Error: Invalid username or password

 

Postman works great after turning off SSL verification. 
I even change the URL to https://url.to.minemeld.com/taxii-poll-service to no avail.

1 REPLY 1

L1 Bithead

For what it is worth, it can be made to work.  ProofPoint TRAP has a few issues.   You will need to build trust on TRAP of the MineMeld root CA (trust the certificate), set TRAP to poll at 1 hour, not 1 minute, or you will periodically consume all RAM within TRAP and then TRAP will fail.   TRAP will stop polling with no indication that it has failed.   The feeds will have green icons indicating feeds are updating, though the logs clearly show no activity.   This requires watching and rebooting TRAP.  

 

I don 't currently have access to the TRAP box.  If I did, I'd share the config.   One thing that was more stable was to create an output feed in MineMeld that was a simple HTTP plain text output feed.   TRAP appeared to handle that type of a feed with less issues.  

  • 3015 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!