Implementing blocklists in the Sekoia SOC platform
ID: 044f69c2-8b2d-56df-9583-8f69c22eff1d
STIX ID: report--044f69c2-8b2d-56df-9583-8f69c22eff1d
Feed Name: Sekoia.com
This article explains how to implement automated blocklists in the Sekoia SOC platform by using IoC Collections (STIX-formatted indicators with validity and revocation), the platform's SOAR automations to push indicators to third-party solutions (firewalls, EDR, SWG), and methods to retrieve collections for native firewall features. It covers recommended practices for collection organization, handling expiration/removal of indicators, and leveraging built-in retro-hunt and playbook templates to streamline dissemination and maintenance of blocklists.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
