Outgoing feed - Cybereason#

Note

This article describes how to configure outgoing feeds for a particular feed source. To see how to configure outgoing feeds in general, see Create and configure outgoing feeds.

Specifications

Transport type

Cybereason push

Content type

Cybereason JSON

Published data

MD5 hashes, domain names, and IP addreses (IPv4, IPv6)

Description

This outgoing feed allows you to push IoCs (Indicators of Compromise) to the Cybereason platform.

Configure the outgoing feed#

  1. Create or edit an outgoing feed.

  2. Under Transport and content, fill out these fields:

    Note

    Required fields are marked with an asterisk (*).

    Field

    Description

    Transport type*

    Select Cybereason push from the drop-down menu.

    Content type*

    Select Cybereason JSON from the drop-down menu.

    Datasets*

    Select an existing dataset from the drop-down menu. The menu only displays datasets that are compatible with the Transport type you’ve selected.

    Update strategy*

    Select an update strategy.

    Username*

    Enter your Cybereason user name.

    Password*

    Enter your Cybereason password.

  3. Store your changes by selecting Save.

View and retrieve outgoing feed content#

  1. Go to the Outgoing feeds view.

  2. In the Outgoing feeds view, click anywhere in the row corresponding to the outgoing feed whose content you want to view or retrieve.

  3. In the selected outgoing feed detail pane, click the Created packages tab.

  4. In the Created packages tab, under the Download column header, click the name of a package to download it, and to save it to a target location.