The Zurich release has arrived! Interested in new features and functionalities? Click here for more

Liju John1
Mega Guru
find_real_file.png


find_real_file.png
find_real_file.png
find_real_file.png

find_real_file.png

Comments
scottlewis
ServiceNow Employee
ServiceNow Employee

Thanks for posting Liju.  You beat me to it!

s

Liju John1
Mega Guru

Thanks for your help Scott.

(I did not see any search result regarding FS-ISAC in the community earlier.)

kmlutz4sn
Kilo Expert

Hello Liju,

Any suggestions or known postings on using data from attack.mitre.org into SN? It seems similar to what you have posted above.

Any suggestions would be appreciated.

Thanks.

Mike_R
Kilo Patron
Kilo Patron

Hi Liju,

 

Thank you for the very helpful instructions. We followed these instructions last year and it worked perfectly.

Apparently in March, FS-ISAC changed the feed URL to "https://taxii.fsisac.com/ctixapi/taxii/". I tried updating the URL & credentials in ServiceNow but am unable to import the data.

 

Any suggestions?

Liju John1
Mega Guru

There is a change in the FS-ISAC APIs.

 

What are the connection parameters for connecting to FS-ISAC’s STIX/TAXII Feed?
• TAXII 1.1:

o Discovery Service: https://taxii.fsisac.com/ctixapi/taxii/
o Collection Service: https://taxii.fsisac.com/ctixapi/taxii/collection/
o Poll Service: https://taxii.fsisac.com/ctixapi/taxii/poll/

• TAXII 2.0:

o Discovery Service: https://taxii.fsisac.com/ctixapi/ctix2/taxii/
o Collection Service: https://taxii.fsisac.com/ctixapi/ctix2/collections/
o Poll Service: https://taxii.fsisac.com/ctixapi/ctix2/collections/<collection_id>/
find_real_file.png

• TAXII 2.1:

  1. o Discovery Service: https://taxii.fsisac.com/ctixapi/ctix21/taxii2/
  2. o Collection Service: https://taxii.fsisac.com/ctixapi/ctix21/collections/
  3. o Poll Service: https://taxii.fsisac.com/ctixapi/ctix21/collections/<collection_id>/
  4. find_real_file.png
Liju John1
Mega Guru

TAXII Collections

Liju John1
Mega Guru

find_real_file.png

Liju John1
Mega Guru

find_real_file.png

Liju John1
Mega Guru

Poll

 

find_real_file.png

Jimmy26
Giga Contributor

Good stuff. I'm going to try this same approach with N-ISAC

Mike_R
Kilo Patron
Kilo Patron

Hi Liju,

 

Thank you for the detailed instructions. I followed all your steps and was able to generate the 10 Taxii Collections. The collections seem to run with no problems "Successfully completed integration run.  No more data to process at this time." but we do not see new data anywhere.

 

Where is this data stored? With the old setup, the data was going to the Indicators and Observables tables but i don't see any new data with this feed.

Version history
Last update:
‎05-21-2019 07:09 PM
Updated by: