Add to TAXII Collections from Library List View
Add to TAXII Collections feature enables analysts to add the selected threat intelligence including observables, indicators, and objects such as attack patterns, threat actors and so on directly to TAXII collections.
Before you begin
Role required: sn_sec_tisc.analyst
About this task
Following is the procedure that shows how to add TAXII collections to an observable.
Procedure
What to do next
Once you add the records to the TAXII collections, navigate to to view the added records under the TAXII Collection Records section. For more information, see Exploring TAXII Outbound Server and Viewing TAXII Collection Records.
When you add a record to a TAXII Collection, the application automatically applies marking definitions to provide additional context about the record.
For example:
If a record has a TLP (Traffic Light Protocol) classification, such as TLP White a related reference record is created to explain what that TLP level means.This ensures that users accessing the shared intelligence are aware of the requirements of each record. When a record is added to a collection, any relevant metadata or contextual records such as TLP markings are automatically created and linked.
In the Administration section, you can view and manage all configuration-related settings, including global exclusion rules. These rules determine which records are automatically excluded from being added to a TAXII Collection.
For example, an exclusion rule might exclude domains marked with TLP Red or TLP Clear. You can customize these rules. For example, you could modify it to exclude only TLP Red records.
- If all selected records match the exclusion rules, the application prevents any records from being added.
- If some records from the selection are valid, then those records are added to the TAXII collection, while the excluded records are automatically filtered out.