Zero Day Live TI FUSION Feed
Zero Day Live TI FUSION Feed Pack.#
This Integration is part of theSupported versions
Supported Cortex XSOAR versions: 6.6.0 and later.
#
OverviewFetch indicators from a ZeroDayLive feed. Zero Day Live is our threat intelligence platform. It services multiple security vendors within the industry with the latest intelligence in order to prevent cyber attacks.
#
Configure ZeroDayLive Feed on Cortex XSOAR- Navigate to Settings > Integrations > Servers & Services.
- Search for Zero Day Live TI FUSION Feed.
- Click Add instance to create and configure a new integration instance.These fields also support the use of API key headers. To use API key headers, specify the header name and value in the following format:
_header:<header_name>
in the Username field and the header value in the Password field. - Click Test to validate the URLs, token, and connection.
#
Step by step configurationAs an example, we'll be looking at the Palo-Alto-sha256 feed. This feed will ingest indicators of type File. These are the feed instance configuration parameters for our example
Indicator Type - File. Server URL: https://digitalwitness.zeroday.live/exports/download/Palo-Alto-sha256.csv. Credentials - user: XXX, password: XXX - need to be obtained from Zero Day Live portal.
The other paramer values can stay with defualt
Field Names - There is only single field and that field is the indicator to fetch. So to confgiure that we can leave default value
as is.