TI platforms

Connect Q-Feeds to ThreatConnect

Install ThreatConnect TAXII Ingest from TC Exchange, then deploy once per collection with Generic mapping and STIX type Indicator.

This article follows the ThreatConnect TAXII Ingest user guide. TAXII needs an Enterprise licence. Credentials: Get your threat feeds. Do not use the older Inbound TAXII Exchange Feed (TAXII 1.x / STIX 1.1).

Prerequisites

  • ThreatConnect: permission to install apps from TC Exchange and run Feed Deployer
  • Q-Feeds: Enterprise TAXII username and password, or Bearer token
  • Network: outbound HTTPS from the ThreatConnect instance to taxii.qfeeds.com on port 443

Q-Feeds values

Feed Deployer fieldValue
Discovery or API roothttps://taxii.qfeeds.com/taxii2/ or https://taxii.qfeeds.com/default
AuthenticationBasic username/password, or Bearer
MappingGeneric (Q-Feeds is not on the named-vendor list)
STIX TypesIndicator only
CollectionOne UUID per deploy

Named mappings in the app (AlienVault, FS-ISAC, H-ISAC, ND-ISAC, ReversingLabs, Space-ISAC, VMRay) do not apply. Generic is what ThreatConnect documents for any other TAXII 2.1 feed.

Install the app

  1. Open TC Exchange Settings, Catalog.
  2. Find ThreatConnect TAXII Ingest and install it. You only install the app once.

Deploy a feed

  1. From Catalog, choose Deploy in the Options column. Feed Deployer opens.
  2. Paste the discovery URL or the API root, plus credentials.
  3. Set Mapping to Generic.
  4. Set STIX Types to Indicator. Leave Campaign, Threat Actor, Report and the rest unchecked.
  5. Select one collection and deploy.
  6. For another collection, return to Catalog and choose Deploy again. ThreatConnect requires one setup per TAXII feed.

What an ingested indicator looks like

Atomic STIX indicators map to native ThreatConnect types: Address, Host, URL and File (hashes). Complex STIX patterns would become Signature Groups of type STIX Pattern; Q-Feeds ships atomic indicators, so you should see the simple types. Search for an Address from the collection after the first run.

Troubleshooting

  • 403: the credentials are not Enterprise.
  • No indicators: Mapping is a named vendor instead of Generic, or STIX Types omitted Indicator.
  • Only one collection arrived: you need a second Deploy for the next UUID.
  • STIX 1.1 errors: you used Inbound TAXII Exchange Feed. Delete that and use TAXII Ingest instead.
  • Support: support@qfeeds.com or the support page.

About the ThreatConnect integration TAXII Feeds & Server

Evaluate our intelligence today!

Simplify your security operations, start your free Q-Feeds trial and experience the difference.

Activate free access