Working with Malware Patrol
The following section describes how to configure Malware Patrol with FortiSIEM for Malware Domains, Malware IPs, Malware Hashes, and Malware URLs. Additional information is available on the Malware Patrol website https://www.malwarepatrol.net/tech-support/.
- Configuring Malware Patrol Malware Domains
- Configuring Malware Patrol Malware IPs
- Configuring Malware Patrol Malware Hashes
- Configuring Malware Patrol Malware URLs
Configuring Malware Patrol Malware Domains
To configure Malware Patrol Malware Domains, take the following steps.
- Login to FortiSIEM GUI.
- Navigate to RESOURCES > Malware Domains.
- In the left pane, click the + icon and create a group named “Malware Patrol”.
- Select the Malware Patrol folder you just created.
- Click More > Update. In the Update Malware dialog box, select Update via API.
- In the URL row, click the Edit icon.
- In the URL field, enter the URL of the threat feed as provided via the Malware Patrol portal.
- In the Username field, enter your Malware Patrol username.
- In the Password field, enter the password associated with your Malware Patrol username.
- In the Plugin Class field, enter:
com.accelops.service.threatfeed.impl.ThreatFeedWithMappingPolicyService
- For Field Separator, enter a comma, by inputting the "," character.
- For Data Format, select CSV.
Note: Currently, only CSV is supported. - Select a Data Update process. Selecting Full means FortiSIEM will download all data. If Incremental is selected, FortiSIEM will download from the latest recorded update date.
- For Data Mapping, add your Mapped fields. The following is an example.
- Domain Name, set to Position 1.
- Malware Type, set to Position 2.
- Description, set to Position 3.
- Date Found, set to Position 4.
- Last Seen, set to Position 5.
- Click Save.
- Schedule the download. See Specifying a Schedule.
- Check the folder 5 minutes after the scheduled time. Downloaded results should be displayed.
Configuring Malware Patrol Malware IPs
To configure Malware Patrol Malware IPs, take the following steps.
- Login to FortiSIEM GUI.
- Navigate to RESOURCES > Malware IPs.
- In the left pane, click the + icon and create a group name “Malware Patrol”.
- Click Save.
- Select the Malware Patrol folder you just created.
- Click More > Update. In the Update Malware IP dialog box, select Update via API.
- In the URL row, click the Edit icon.
- In the URL field, enter the URL of the threat feed as provided via the Malware Patrol portal.
- In the Username field, enter your Malware Patrol username.
- In the Password field, enter the password associated with your Malware Patrol username.
- In the Plugin Class field, enter:
com.accelops.service.threatfeed.impl.ThreatFeedWithMappingPolicyService
- For Field Separator, enter a comma, by inputting the "," character.
- For Data Format, select CSV.
Note: Currently, only CSV is supported. - Select a Data Update process. Selecting Full means FortiSIEM will download all data. If Incremental is selected, FortiSIEM will download from the latest recorded update date.
- For Data Mapping, add your Mapped fields. The following is an example.
- Name, set to Position 1.
- Low IP , set to Position 2.
- High IP, set to Position 3.
- Malware Type, set to Position 4.
- Description, set to Position 5.
- Date Found, set to Position 6.
- Last Seen, set to Position 7.
- Click Save.
- Schedule the download. See Specifying a Schedule.
- Check the folder 5 minutes after the scheduled time. Downloaded results should be displayed.
Configuring Malware Patrol Malware Hashes
To configure Malware Patrol Malware Hashes, take the following steps.
- Login to FortiSIEM GUI.
- Navigate to RESOURCES > Malware Hash.
- In the left pane, click the + icon and create a group name “Malware Patrol”.
- Click Save.
- Select the Malware Patrol folder you just created.
- Click More > Update. In the Update Malware Hash dialog box, select Update via API.
- In the URL row, click the Edit icon.
- In the URL field, enter the URL of the threat feed as provided via the Malware Patrol portal.
- In the Username field, enter your Malware Patrol username.
- In the Password field, enter the password associated with your Malware Patrol username.
- In the Plugin Class field, enter:
com.accelops.service.threatfeed.impl.ThreatFeedWithMappingPolicyService
- For Field Separator, enter a comma, by inputting the "," character.
- For Data Format, select CSV.
Note: Currently, only CSV is supported. - Select a Data Update process. Selecting Full means FortiSIEM will download all data. If Incremental is selected, FortiSIEM will download from the latest recorded update date.
- For Data Mapping, add your Mapped fields. The following is an example.
- Description, set to Position 1.
- Algorithm, set to Position 2.
- HashCode, set to Position 3.
- Malware Type, set to Position 4.
- Date Found, set to Position 5.
- Last Seen, set to Position 6.
- Click Save.
- Schedule the download. See Specifying a Schedule.
- Check the folder 5 minutes after the scheduled time. Downloaded results should be displayed.
Configuring Malware Patrol Malware URLs
To configure Malware Patrol Malware URLs, take the following steps.
- Login to FortiSIEM GUI.
- Navigate to RESOURCES > Malware URLs.
- In the left pane, click the + icon and create a group name “Malware Patrol”.
- Click Save.
- Select the Malware Patrol folder you just created.
- Click More > Update. In the Update Malware Url dialog box, select Update via API.
- In the URL row, click the Edit icon.
- In the URL field, enter the URL of the threat feed as provided via the Malware Patrol portal.
- In the Username field, enter your Malware Patrol username.
- In the Password field, enter the password associated with your Malware Patrol username.
- In the Plugin Class field, enter:
com.accelops.service.threatfeed.impl.ThreatFeedWithMappingPolicyService
- For Field Separator, enter a comma, by inputting the "," character.
- For Data Format, select CSV.
Note: Currently, only CSV is supported. - Select a Data Update process. Selecting Full means FortiSIEM will download all data. If Incremental is selected, FortiSIEM will download from the latest recorded update date.
- For Data Mapping, add your Mapped fields. The following is an example.
- URL, set to Position 1.
- Malware Type, set to Position 2.
- Last Seen, set to Position 3.
- Click Save.
- Schedule the download. See Specifying a Schedule.
- Check the folder 5 minutes after the scheduled time. Downloaded results should be displayed.