Working with Dragos IOCs
The following sections describe how to work with Dragos Worldview malware malware domains, IPs, and hashes.
- Download Dragos Worldview Malware Domains
- Download Dragos Worldview Malware IPs
- Download Dragos Worldview Malware Hashes
Download Dragos Worldview Malware Domains
- Go to RESOURCES > Malware Domains and select the Dragos Worldview Malware Domain folder.
- Click More > Update. In the Update Malware dialog box, then select Update via API.
- Use your Dragos credentials to complete the URL, API Token, and API Secret fields.
- Plugin Class is provided by default.
- Select a Data Format. In this release, only Custom is supported.
- Select a Data Update process. Selecting Full means FortiSIEM will download all data. If Incremental is selected, FortiSIEM will download from the latest recorded update date.
- Click Save.
- Schedule the download. See Specifying a Schedule.
- Check the folder 5 minutes after the scheduled time. Downloaded results should be displayed.
Download Dragos Worldview Malware IPs
- Go to RESOURCES > Malware IPs, select the Dragos Worldview Malware IP folder.
- Click More > Update. In the Update Malware dialog box, then select Update via API.
- Use your Dragos credentials to complete the URL, API Token, and API Secret fields.
- Plugin Class is provided by default.
- Select a Data Format. In this release, only Custom is supported.
- Select a Data Update process. Selecting Full means FortiSIEM will download all data. If Incremental is selected, FortiSIEM will download from the latest recorded update date.
- Click Save.
- Schedule the download. See Specifying a Schedule.
- Check the folder 5 minutes after the scheduled time. Downloaded results should be displayed.
Download Dragos Worldview Malware Hashes
- For Dragos Worldview hash, go to RESOURCES > Malware Hash , select the Dragos Worldview Malware Hash folder.
- Click More > Update. In the Update Malware dialog box, then select Update via API.
- Use your Dragos credentials to complete the URL, API Token, and API Secret fields.
- Plugin Class is provided by default.
- Select a Data Format. In this release, only Custom is supported.
- Select a Data Update process. Selecting Full means FortiSIEM will download all data. If Incremental is selected, FortiSIEM will download from the latest recorded update date.
- Click Save.
- Schedule the download. See Specifying a Schedule.
- Check the folder 5 minutes after the scheduled time. Downloaded results should be displayed.
Specifying a Schedule
- Click the + icon next to Schedule.
- Enter values for the following options:
- Time Range specifies start time (within the day) and the duration of the scheduling window. Select a UTC time and a corresponding location from the drop-down lists.
- Recurrence Pattern specifies if and
how the window will repeat.
- If you are scheduling for one time
only:
- Select Once for Recurrence Pattern.
- Select the specific date in Start From.
- If you are scheduling for hourly:
- Enter the hourly interval.
- Select the Start From date for Recurrence Range, then either End after the number of occurrences, and End by date, or No end date to continue the recurrence forever.
- If you are scheduling for Daily:
- Select the interval of days or Every weekday.
- Select the Start From date for Recurrence Range, then either End after the number of occurrences, and End by date, or No end date to continue the recurrence forever.
- If you are scheduling for Weekly:
- Select the interval of weeks or select particular days of the week.
- Select the Start From date for Recurrence Range, then either End after the number of occurrences, and End by date, or No end date to continue the recurrence forever.
- If you are scheduling for Monthly:
- Select the days and months from the drop-down lists.
- Select the Start From date for Recurrence Range, then either End after the number of occurrences, and End by date, or No end date to continue the recurrence forever.
- If you are scheduling for one time
only:
- Click Save to apply the changes.