Threat intelligence TAXII

Copper Contributor

I am trying to add the Threat intelligence - TAXII connector in Sentinel. Upon entering the asked details such as mentioned below:

Friendly Name: TAXIIFeeds

APIhttps://limo.anomali.com/api/v1/taxii2/feeds/

Collection ID: 107 (tried by entering 135, 136 as well)

Username: guest

Password: guest

 

Selected Import Indicator as All Available(tried other options as well) and Polling Frequency as Once a day (tried other options as well). 

 

Post entering the above mentioned details, when I click Add,  I am getting error as "TAXII connector already exists with the same API root URL and Collection ID or inputs are not valid."

 

It seems the API https://limo.anomali.com/api/v1/taxii2/feeds/ is no more valid. When I try to open, it throws an error as "This site can’t be reached". Also, this URL (https://www.anomali.com/resources/limo)  it says the API URL is changed.

 

Not sure where the issue is. Can someone help on this please. 

 

Best regards.

6 Replies

Hello @mujju016,

 

It seems that Limo has reached the end of the road.

Limo - Free Intel Feed by Anomali - Learn More

Are you trying to use the free version of Limo? 

I am using the same as per mentioned by Microsoft.

Is there any other way for this? please guide.
Where do you see that Limo was mentioned by Microsoft?
This service stopped providing free indicators. I think because of that you have an issue.
I saw a YouTube video from the Microsoft Security channel. the link is : https://www.youtube.com/watch?v=3nCDOJ9D2Q8

aside, can you pls share your insights on how to integrate the Threat intelligence - TAXII into Azure Sentinel ?

This would be of great help!

@mujju016 

 

There are also 2 options to ingest TI from Alien Vault:

1. Using Logic App:

Ingesting Alien Vault OTX Threat Indicators into Azure Sentinel - Microsoft Community Hub

Azure-Sentinel/Playbooks/Get-AlienVault_OTX at master · Azure/Azure-Sentinel · GitHub

2. Using TAXII:

You need to create an account on Alien Vault, generate an API key, and then connect Alien Vault TAXI.