This article follows the ThreatConnect TAXII Ingest user guide. TAXII needs an Enterprise licence. Credentials: Get your threat feeds. Do not use the older Inbound TAXII Exchange Feed (TAXII 1.x / STIX 1.1).
Prerequisites
- ThreatConnect: permission to install apps from TC Exchange and run Feed Deployer
- Q-Feeds: Enterprise TAXII username and password, or Bearer token
- Network: outbound HTTPS from the ThreatConnect instance to
taxii.qfeeds.comon port 443
Q-Feeds values
| Feed Deployer field | Value |
|---|---|
| Discovery or API root | https://taxii.qfeeds.com/taxii2/ or https://taxii.qfeeds.com/default |
| Authentication | Basic username/password, or Bearer |
| Mapping | Generic (Q-Feeds is not on the named-vendor list) |
| STIX Types | Indicator only |
| Collection | One UUID per deploy |
Named mappings in the app (AlienVault, FS-ISAC, H-ISAC, ND-ISAC, ReversingLabs, Space-ISAC, VMRay) do not apply. Generic is what ThreatConnect documents for any other TAXII 2.1 feed.
Install the app
- Open TC Exchange Settings, Catalog.
- Find ThreatConnect TAXII Ingest and install it. You only install the app once.
Deploy a feed
- From Catalog, choose Deploy in the Options column. Feed Deployer opens.
- Paste the discovery URL or the API root, plus credentials.
- Set Mapping to Generic.
- Set STIX Types to Indicator. Leave Campaign, Threat Actor, Report and the rest unchecked.
- Select one collection and deploy.
- For another collection, return to Catalog and choose Deploy again. ThreatConnect requires one setup per TAXII feed.
What an ingested indicator looks like
Atomic STIX indicators map to native ThreatConnect types: Address, Host, URL and File (hashes). Complex STIX patterns would become Signature Groups of type STIX Pattern; Q-Feeds ships atomic indicators, so you should see the simple types. Search for an Address from the collection after the first run.
Troubleshooting
- 403: the credentials are not Enterprise.
- No indicators: Mapping is a named vendor instead of Generic, or STIX Types omitted Indicator.
- Only one collection arrived: you need a second Deploy for the next UUID.
- STIX 1.1 errors: you used Inbound TAXII Exchange Feed. Delete that and use TAXII Ingest instead.
- Support: support@qfeeds.com or the support page.