You can add or edit a TAXII feed you want to subscribe to.
The TAXII Feeds screen appears.
To add a feed, click Add.
To edit a feed, click the feed name.
TAXII 2.0 and 2.1 are supported. The TAXII server version cannot be modified once the feed has been added.
If you enable the option, click and select one or more of
the following object types to extract from the collections and add
to the Suspicious Object List:
Domain
File SHA-1
File SHA-256
IP address
Sender address
URL
By default, these suspicious objects are considered as high-risk objects that expire in 30 days. The connected products receive the new object information from Trend Vision One during the next synchronization, and will take the "Block/Quarantine" action after detecting those objects.
Only "indicator" type objects that are not labeled as "anomalous-activity", "anonymization", "benign", "compromised", or "unknown", and that are not revoked will be added to the Suspicious Objects List.
Enabling this option initiates a one-time Auto Sweeping task that runs right after successful subscription to search your historical data for any indicators extracted from the current collection.
The TAXII feed appears on the TAXII Feeds screen and will be processed to produce custom intelligence reports. To further check the reports generated from your feed subscriptions, go to Threat Intelligence > Intelligence Reports and click the Custom tab.