Knowledge packs#
Introduction#
Knowledge packs provide pre-defined configurations or packs, that equip Intelligence Center (IC) users with the ability to address their threat research and investigations through expert-curated workspaces and datasets.
Knowledge packs come with a set of packs created by EclecticIQ’s threat research team as a culmination of their vast research experience and expertise.
As of version 2.11, Intelligence Center users can create their own knowledge packs. Users can create these knowledge packs and share them with their consumers.
Requirements#
Permissions#
The following permissions are required to use knowledge packs. To see your permissions, go to, Settings () > User management > Permissions. See Permissions for more information on the permission settings for knowledge packs.
Permissions |
Description |
---|---|
|
Can install knowledge packs. Must have both this and
|
|
Can view knowledge packs. |
|
Can modify knowledge packs as a Producer. |
Allow outgoing connections to EclecticIQ#
To allow your IC instance to retrieve knowledge packs from the EclecticIQ producer, allow outgoing requests to:
https://cti.eclecticiq.com/configuration-bundles/producer
https://cti.eclecticiq.com/configuration-bundles/published
Knowledge pack consumers and producers#
Intelligence Center users can create their own knowledge packs for dissemination to their users, fully customized to their own requirements and priorities. Knowledge pack creators are designated as producers. Users that install and use the packs created by producers are called consumers.
To be a producer, you must:
Enable (Beta) Producer. See below for more information.
Have
modify knowledge-packs
permissions
Note
The CREATED PACKS tab is visible only if
(Beta) Producer is enabled, and you have
modify knowledge-packs
permissions.
(Beta) Producers#
This section describes how to create and manage knowledge packs.
Enable the producer beta#
Note
This feature is still in beta.
To enable knowledge pack creation and set up a producer:
From the left navigation bar, go to Settings()> System settings > General.
Select EDIT SETTINGS.
Select the Enable knowledge packs creation checkbox.
The Producer name field appears.
Enter the producer’s name.
Producer name is a mandatory field.
The name entered here is shown as a producer on the consumer’s IC instance.
Select SAVE.
Create knowledge packs#
To create a knowledge pack:
From the left navigation bar, go to Data configuration ()> Knowledge packs > CREATED PACKS.
Select Create Knowledge Pack (+).
Fill out these fields:
Field name
Description
Name
Name of knowledge pack.
Description
Enter a description for this knowledge pack.
Select ADD EXISTING.
In the Select objects window that appears, select the objects to add to your knowledge pack.
Select CONFIRM.
Select SAVE.
The knowledge pack created is listed in the CREATED PACKS tab.
Publish knowledge packs#
To make a knowledge pack available to consumers, you must:
Publish the knowledge pack.
Share the knowledge packs endpoint URL for your Intelligence Center instance.
To publish a knowledge pack:
Select a knowledge pack in the CREATED PACKS tab to open it.
Select PUBLISH.
To share your knowledge packs endpoint URL:
Edit and update knowledge packs#
To edit and update a knowledge pack:
Unpublish the pack if it is in the published state.
Add or remove the objects as required.
Publish the pack again.
Unpublish knowledge packs#
To unpublish a knowledge pack:
Note
When you unpublish a pack:
The pack becomes unavailable to the consumers. It is no longer displayed in MY LIBRARY in their IC instance.
Consumers that have already enabled the pack can continue to use it in their Intelligence Center instances.
Consumers#
This section describes the operations available for the consumers and the producers.
Add producers#
To see knowledge packs from a given producer, you must add that producer to your IC.
To add a producer:
In the MY LIBRARY tab, select Manage producers .
This opens the Producers management modal and displays a list of previously added producers.
Enter the knowledge packs endpoint URL of the producer you want to add.
Select ADD.
Tip
By default, the EclecticIQ producer is added on IC instances.
To allow your IC instance to retrieve knowledge packs from the EclecticIQ producer, allow outgoing requests to:
https://cti.eclecticiq.com/configuration-bundles/producer
https://cti.eclecticiq.com/configuration-bundles/published
Remove producers#
To remove producers:
Enable a knowledge pack#
In the MY LIBRARY tab, locate a knowledge pack to enable.
On the right of that knowledge pack:
Follow the instructions that appear.
When prompted, select one or more groups to grant access to the knowledge pack.
Note
This shares the knowledge pack itself with the members of that group. However, group members still need to be granted access to the underlying objects distributed by the knowledge packs.
Select DONE.
Disable a knowledge pack#
Known limitations#
Knowledge packs is considered a beta feature. The following is a list of known limitations that EclecticIQ intends to address in the upcoming releases:
No authentication
At present, knowledge packs are unauthenticated.
Synchronizing updates to consumers.
Producers cannot synchronize updates to a consumer when:
A pack has been published by a producer.
In order to synchronize updates for a published pack, producers must unpublish and then publish the pack.
The pack is already enabled on a consumer.
In order to receive an updated version of a pack, the consumer must disable and then enable it.
Versioning knowledge packs is not possible at present.
Deleting an object from EclecticIQ Intelligence Center does not remove it from a knowledge pack.
When a producer deletes an object (e.g. a rule, a dataset, or a workspace) that is part of a knowledge pack, the object is not removed from the knowledge pack.