Implementing blocklists in the Sekoia SOC platform
ID: cd5c0cf9-c8ae-5d11-a9a6-c5b82d377521
STIX ID: report--cd5c0cf9-c8ae-5d11-a9a6-c5b82d377521
Feed Name: Sekoia.io Blog (archive)
This document outlines how to implement and automate IoC-based blocklists using the Sekoia SOC platform, replacing legacy approaches like Minemeld. It covers organizing IoCs in STIX-based collections with validity and revocation, leveraging detection and retro-hunt capabilities, and disseminating indicators to firewalls (via external lists) and other security tools (EDR/SWG) through native SOAR automations, including handling indicator expirations where supported.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
