Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

TIDE data can be uploaded to a profile associated with an account. Policies are used to control access to your organization's data and can be specified when the data is submitted. Data Policies allow organizations to control how their submitted data is shared with other organizations or groups. Infoblox can enable accessing and data sharing between organizations upon request. Policies can be used for multiple data submissions and are only visible within your organization. Data profiles are used to identify data in the platform from one or many data submissions. A data profile must be specified when data is submitted. Data profiles are associated with policies, which control who can access the data. When a data profile is created it must be associated with a policy.


Note

A dedicated service key for each data output is the recommended best practice.


Users can submit threat indicators using the Cloud Services Portal or via the TIDE Data API. In order to submit data, the following is required:

...

Data Submission Formats

Note
titleNote

Any unknown fields in a record will automatically go under an “extended” field for that record. This will occur after the submission is done. 


Threat Data Fields
File-level fields
profile

data profile id or name

record_typehost, ip, or url
external_idstring indicating an external ID to assign to the batch
recordsurrounds the individual record(s) in the XML and JSON formats
Record-level fields
Field NameDescription
hostthreat hostname
ipthreat IP address
urlthreat URL
hashhash threat
emailemail threat
detecteddate/time threat was detected, in ISO 8601 format
classthe threat's class, for example: Sinkhole
propertythe threat's property, for example: Sinkhole_SinkholedHost
confidence

the threat's confidence score ranging from 0 - 100 (optional)

domaindomain string (optional)
durationduration of the threat in XyXmXwXdXh format - the expiration date will be set to the detected date + this duration (optional)
expiration expiration date, in ISO 8601 format (optional)
threat_levelthe threat's level, ranging from 0 - 100 (optional)
targettarget of threat (optional)
tldtop-level domain, string (optional) 

...