Questions About the TAXII2 Data Connector

%3CLINGO-SUB%20id%3D%22lingo-sub-1458423%22%20slang%3D%22en-US%22%3EQuestions%20About%20the%20TAXII2%20Data%20Connector%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1458423%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20there%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20am%20currently%20working%20on%20developing%20a%20TAXII2%20server%20implementation%20and%20plan%20to%20connect%20it%20to%20my%20Sentinel%20instance.%20I%20have%20done%20a%20number%20of%20tests%20and%20I%20can%20currently%20feed%20in%20most%20indicators%2C%20but%20still%20have%20some%20questions%20and%20want%20to%20get%20a%20better%20idea%20of%20how%20the%20connector%20works.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3COL%3E%3CLI%3E%26nbsp%3BCan%20the%20Azure%20Sentinel%20connector%20also%20accept%20STIX2%20observed%20data%20objects%3F%20I%20remember%20watching%20a%20webinar%20presented%20by%20Jason%20Wescott%20where%20he%20said%20you%20can%20feed%20in%20observed%20data%20and%20indicators%20CTIs%20into%20Sentinel%20but%20I%20have%20not%20been%20able%20to%20achieve%20this.%20I%20have%20tried%20both%20the%20deprecated%20STIX%20v2.0%20objects%20property%20and%20the%20STIX%20v2.1%20object_refs%2C%20but%20neither%20seem%20to%20completely%20work%20100%25.%20Using%20the%20object_refs%20property%20does%20result%20in%20some%20of%20the%20data%20being%20imported%20in%2C%20but%20not%20all%20of%20it.%3C%2FLI%3E%3CLI%3EWhat%20is%20the%20naming%20convention%20for%20file%20hash%20types%20used%20by%20the%20Sentinel%20TAXII%20client%3F%20I%20have%20tried%20the%20format%20specified%20in%20the%20TAXII2%20specification%2C%20but%20Sentinel%20cannot%20correctly%20identify%20the%20hash%20type%20and%20just%20says%20it%20is%20Unknown.%20For%20an%20example%20if%20Sentinel%20tries%20to%20import%20the%20following%20pattern%3A%26nbsp%3B%3C%2FLI%3E%3C%2FOL%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CPRE%20class%3D%22lia-code-sample%20language-json%22%3E%3CCODE%3E%22%5Bfile%3Ahashes.'SHA-256'%20%3D%20'ef537f25c895bfa782526529a9b63d97aa631564d5d789c2b765448c8635fb6c'%5D%22%E2%80%8B%3C%2FCODE%3E%3C%2FPRE%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIt%20will%20correctly%20get%20the%20hash%20from%20the%20pattern%2C%20but%20cannot%20identify%20that%20the%20hash%20is%20of%20type%20SHA-256.%3C%2FP%3E%3CUL%3E%3CLI%3EHow%20frequent%20does%20the%20data%20connector%20check%20for%20updates%20on%20the%20TAXII2%20server%3F%20When%20I%20make%20a%20new%20connection%2C%20it%20gets%20all%20of%20the%20STIX2%20objects%20stored%20on%20the%20TAXII2%20server%2C%20then%20does%20not%20check%20for%20some%20time.%20Other%20times%20it%20starts%20checking%20periodically%20every%20minute.%3C%2FLI%3E%3C%2FUL%3E%3CP%3EThose%20are%20the%20main%20questions%20I%20have%20about%20the%20connector%20for%20now%2C%20I%20will%20probably%20be%20back%20soon%20with%20more.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1462644%22%20slang%3D%22en-US%22%3ERe%3A%20Questions%20About%20the%20TAXII2%20Data%20Connector%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1462644%22%20slang%3D%22en-US%22%3E%3CP%3ETagging%20%3CSPAN%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F118392%22%20target%3D%22_blank%22%3E%40Jason%20Wescott%3C%2FA%3E%26nbsp%3Bto%20look%20into%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
New Contributor

Hi there,

 

I am currently working on developing a TAXII2 server implementation and plan to connect it to my Sentinel instance. I have done a number of tests and I can currently feed in most indicators, but still have some questions and want to get a better idea of how the connector works.

 

  1.  Can the Azure Sentinel connector also accept STIX2 observed data objects? I remember watching a webinar presented by Jason Wescott where he said you can feed in observed data and indicators CTIs into Sentinel but I have not been able to achieve this. I have tried both the deprecated STIX v2.0 objects property and the STIX v2.1 object_refs, but neither seem to completely work 100%. Using the object_refs property does result in some of the data being imported in, but not all of it.
  2. What is the naming convention for file hash types used by the Sentinel TAXII client? I have tried the format specified in the TAXII2 specification, but Sentinel cannot correctly identify the hash type and just says it is Unknown. For an example if Sentinel tries to import the following pattern: 

 

"[file:hashes.'SHA-256' = 'ef537f25c895bfa782526529a9b63d97aa631564d5d789c2b765448c8635fb6c']"​

 

It will correctly get the hash from the pattern, but cannot identify that the hash is of type SHA-256.

  • How frequent does the data connector check for updates on the TAXII2 server? When I make a new connection, it gets all of the STIX2 objects stored on the TAXII2 server, then does not check for some time. Other times it starts checking periodically every minute.

Those are the main questions I have about the connector for now, I will probably be back soon with more.

1 Reply
Highlighted

Tagging @Jason Wescott to look into