Intergrations of External Dynamic Lists (EDL) with External Systems

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Intergrations of External Dynamic Lists (EDL) with External Systems

L0 Member

Hi! I’m looking for guidance on whether entries from External Dynamic Lists (EDL) in Palo Alto Networks can be programmatically accessed or integrated with external systems for broader threat intelligence use.

 

Specifically, I would like to understand:

Whether EDL contents (IP, domain, URL indicators) can be retrieved via API or another supported method.

If there is a way to export or query EDL data in near real-time or on a scheduled basis.

Whether Palo Alto provides any native integrations or mechanisms to share EDL-derived intelligence with external platforms.

 

Use Cases:

We are working toward centralizing and reusing threat intelligence across multiple security controls and platforms.

Some example use cases include:

 

Azure Integration

Continuously ingest Tor exit node IPs into an EDL within Palo Alto

Reuse that same dataset to update Azure controls (Conditional Access, Named Locations, or other access restrictions) to block access to cloud resources from Tor networks

 

MISP Integration

Leverage EDL data as a source of indicators for ingestion into MISP

Enrich or correlate EDL indicators with existing intelligence in MISP

Use MISP as a central repository while maintaining Palo Alto as an enforcement point


Additional Questions:

Are there recommended architectures or best practices for synchronizing EDL-based intelligence with external systems such as Azure or MISP?

 

Are there any limitations or considerations around using EDLs as a source of truth for downstream integrations?


Would Palo Alto recommend an alternative approach (Cortex XSOAR, Cortex XDR, or other integrations) for distributing threat intelligence across multiple environments?


If direct access to EDL contents is not supported, are there indirect methods (via logs, Cortex Data Lake, or other telemetry) that could be leveraged to operationalize this data externally?

 

(✿◠‿◠) ♡ Sarah ♡ (◠‿◠✿)
1 accepted solution

Accepted Solutions

Cyber Elite

Hi @SarahEubanks ,

 

Whether EDL contents (IP, domain, URL indicators) can be retrieved via API or another supported method?  Yes

 

https://yo.ur.hg.fw/api/?type=op&cmd=<request><system><external-list><show><type><predefined-ip><num-records>10000</num-records><name>panw-torexit-ip-list</name></predefined-ip></type></show></external-list></system></request>

 

Here are a few notes:

myname@myngfw(active)> request system external-list show type predefined-ip name 
  panw-bulletproof-ip-list   panw-bulletproof-ip-list
  panw-highrisk-ip-list      panw-highrisk-ip-list
  panw-known-ip-list         panw-known-ip-list
  panw-torexit-ip-list       panw-torexit-ip-list
  <name>                     <name>

 

If there is a way to export or query EDL data in near real-time or on a scheduled basis?  Yes.  The API query on the largest predefined IP list took about 1 second.

 

Whether Palo Alto provides any native integrations or mechanisms to share EDL-derived intelligence with external platforms?  I don't think there are integrations native to PAN-OS.

 

Would Palo Alto recommend an alternative approach (Cortex XSOAR, Cortex XDR, or other integrations) for distributing threat intelligence across multiple environments?  I'm sure they would recommend Cortex XSOAR.  It has a LOT more features and includes the predefined EDLs.  https://xsoar.pan.dev/docs/reference/index  (Search for "predefined edl").  You may need the TIM (Threat Intelligence Management) license.  I am not sure.  https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-SaaS-Documentation/Understand...

 

Are there any limitations or considerations around using EDLs as a source of truth for downstream integrations?  Not that I know.

 

Are there recommended architectures or best practices for synchronizing EDL-based intelligence with external systems such as Azure or MISP?  There are best practice guides for Cortex XSOAR.  With regard to automation, there are a million ways to do it.  It sounds like you are starting at a good place and will grow from there.

 

Thanks,

 

Tom

Help the community: Like helpful comments and mark solutions.

View solution in original post

1 REPLY 1

Cyber Elite

Hi @SarahEubanks ,

 

Whether EDL contents (IP, domain, URL indicators) can be retrieved via API or another supported method?  Yes

 

https://yo.ur.hg.fw/api/?type=op&cmd=<request><system><external-list><show><type><predefined-ip><num-records>10000</num-records><name>panw-torexit-ip-list</name></predefined-ip></type></show></external-list></system></request>

 

Here are a few notes:

myname@myngfw(active)> request system external-list show type predefined-ip name 
  panw-bulletproof-ip-list   panw-bulletproof-ip-list
  panw-highrisk-ip-list      panw-highrisk-ip-list
  panw-known-ip-list         panw-known-ip-list
  panw-torexit-ip-list       panw-torexit-ip-list
  <name>                     <name>

 

If there is a way to export or query EDL data in near real-time or on a scheduled basis?  Yes.  The API query on the largest predefined IP list took about 1 second.

 

Whether Palo Alto provides any native integrations or mechanisms to share EDL-derived intelligence with external platforms?  I don't think there are integrations native to PAN-OS.

 

Would Palo Alto recommend an alternative approach (Cortex XSOAR, Cortex XDR, or other integrations) for distributing threat intelligence across multiple environments?  I'm sure they would recommend Cortex XSOAR.  It has a LOT more features and includes the predefined EDLs.  https://xsoar.pan.dev/docs/reference/index  (Search for "predefined edl").  You may need the TIM (Threat Intelligence Management) license.  I am not sure.  https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-SaaS-Documentation/Understand...

 

Are there any limitations or considerations around using EDLs as a source of truth for downstream integrations?  Not that I know.

 

Are there recommended architectures or best practices for synchronizing EDL-based intelligence with external systems such as Azure or MISP?  There are best practice guides for Cortex XSOAR.  With regard to automation, there are a million ways to do it.  It sounds like you are starting at a good place and will grow from there.

 

Thanks,

 

Tom

Help the community: Like helpful comments and mark solutions.
  • 1 accepted solution
  • 604 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!