StixTaxii
PremiumStixTaxii is a threat intelligence source that fetches Cyber Threat Intelligence (CTI) data written in STIX format from a TAXII server. You can enrich incoming logs of Logpoint with this fetched data by using the Threat Intelligence process command. StixTaxii supports STIX/TAXII versions 1.0, 2.0 and 2.1.
Release Details
Key Information
In Director, support for selecting specific collections from the TAXII server will be available from v2.10.0.
Enhancement
PLUG-16464, PLUG-17342
You can now select specific collections to ingest from the TAXII v2.1 Discovery URL.
Bug Fix
PLUG-16396
When collecting from sources with many collections, the collection failed with “too many requests” due to high concurrency, interrupting threat intelligence collection.
Past Releases
StixTaxii v6.3.1 ▾
Enhancement
PLUG-15922
StixTaxii is now compatible with Logpoint 7.6.0.
StixTaxii v6.3.0 ▾
Bug Fixes
PLUG-849863074
The StixTaxii proxy failed to function without manually updating its configuration file from https:// to http://.
PLUG-1176282003
The URL field value was incorrectly parsed as h://tt instead of the original url value.
StixTaxii v6.2.1 ▾
Bug Fixes
PLUG-1310685242, 85349
For TAXII v1.0, the STIX_Header was mandatory, resulting in logs not being fetched if the field was empty.
PLUG-1196383617
For TAXII v2.X, StixTaxii failed to parse log data with JSON objects containing “type“: “ipv4-addr“, resulting in them not being fetched.
StixTaxii v6.2.0 ▾
Enhancement
PLUG-11194
You can now enable pagination to fetch data in a paginated manner, allowing for easier navigation and management of large datasets. For details on enabling, go to settings .
StixTaxii v6.1.0 ▾
Enhancement
PLUG-10245
StixTaxii now supports STIX/TAXII v2.1.
StixTaxii v6.0.0 ▾
Enhancement
The application has been updated to comply with LogPoint v6.12.2.
Support
If you have any questions or require assistance, create a support ticket.
Comments
Article is closed for comments.