STIX/TAXII (Beta)
Enrich incoming events with indicators of compromise from a STIX/TAXII 2.1 server
Overview
How STIX/TAXII enrichment works in Panther
How a match between a log event and STIX/TAXII is made
Setting up STIX/TAXII enrichment
Step 1: Gather your TAXII server details
Step 2: Create the STIX/TAXII enrichment in Panther

The "What type of enrichment would you like to setup" screen shows Custom Enrichment options followed by a grid of Supported Enrichments, including Anomali, Open Threat Exchange, GreyNoise, Google Threat Intelligence, VirusTotal, and STIX/TAXII (circled), Snowflake Audit, Google Workspace, and Okta. 
The Enrichment Settings step shows fields for Name, TAXII Discovery URL, Authentication Method (Bearer Token or Basic Auth), API Token, and Indicator TTL (Max age in Days), along with a notice displaying Panther's egress IP. 
The Select Collections step shows an Enrichment Info sidebar with the previously entered settings, and a Select Collections panel with a filter box and a table of discovered collections, each with a checkbox, Collection Name, and Description.
Managing collections after setup

The Collections tab of a STIX/TAXII enrichment shows a table of enabled collections, each with a Collection Name and Description, and an Edit Collections button in the upper-right.
Enabling, disabling, or modifying STIX/TAXII enrichment for a log type
Example STIX/TAXII enrichment table entry
STIX.Indicator schema
Example of using STIX/TAXII data in detections
Troubleshooting STIX/TAXII enrichment
Common issues
Last updated
Was this helpful?

