Incoming feed - OpenPhish
This procedure describes how to configure incoming feeds for a particular feed data source, transport type, or content type.
For more information about configuring common options shared across all incoming feeds, see Configure incoming feeds general options.
|
Specifications |
Transport type |
OpenPhish Feed |
Content type |
OpenPhish Feed Text |
Ingested data |
Ingests the freely available OpenPhish Community feed, a list of phishing and compromised URLs. |
Processed data |
URLs are saved as indicators. |
Description |
Ingest information about phishing sites and compromised URLs. |
Configure the incoming feed
Create and edit an incoming feed.
From the Transport type drop-down menu, select OpenPhish Feed.
From the Content type drop-down menu, select OpenPhish Feed Text.
The OpenPhish Feed transport type supports only the OpenPhish Feed Text content type.The API URL field is automatically filled in with the default domain for the endpoint.
You can add a proxy or set up ports according to your needs.
Default value: https://openphish.com/feed.txt.To store your changes, click Save; to discard them, click Cancel.
Test the feed
In the top navigation bar, click Data Configuration > Incoming feeds.
Click the feed that you just created, using the steps above.
In the Overview view, click Download now.
Click Ingested entities and check that entities have been ingested into the platform.
Or:
In the top navigation bar, click Intelligence > All intelligence > Browse.
Click the Entities tab.
In the top-left corner, click .
From the Source drop-down menu, select the incoming feed you have just created, using the steps.
You can also filter also by entity type: from the Entity drop-down menu, select the entity types you want to include in the filtered results.