Splunk Enterprise Security

Default Threat Intelligence feeds not visible in ES

neerajs_81
Builder

Hello,
As per ES official documentation, it says below threat intel feeds are enabled by default. 

  • Mozilla Public Suffix List
  • MITRE ATT&CK Framework
  • ICANN Top-level Domains List

In addition it also mentions these are  included

neerajs_81_1-1633500461436.png

 

But when i check in our ES app settings >> Threat Intel management page, i see only 3 feeds as below.  Where are those default feeds mentioned above ?

neerajs_81_0-1633500373811.png

 

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...