Prerequisites
- Splunk ES with Threat Intelligence Management
- API key from reyhford.com/portal
Configure TAXII feed
- In Splunk ES, go to Configure → Content → Threat Intelligence Management → New Threat Intelligence Collection.
- Select TAXII as the source type.
- Enter server details:
- Set polling interval to 15–60 minutes.
- Enable Use added_after for incremental updates.
Collections
STIX 2.1 objects
Reyhford returns STIX 2.1indicator objects with:
ipv4-addr— attacking IPnetwork-traffic— port and protocolautonomous-system— ASN and organizationlocation— countryindicator— STIX pattern, MITRE kill chain phase, confidence scoresighting— observation count, first and last seen
Verification
Troubleshooting
Empty feed
Empty feed
New sensors take a few minutes to produce enriched indicators. Check status.reyhford.com.
Only seeing SSH/SMB, no ICS protocols
Only seeing SSH/SMB, no ICS protocols
Switch collection from
global-feed to ics-feed.