Mandiant Module
The Mandiant module enables you to synchronize your DocIntel instance with your Mandiant Threat Intelligence Feed. All the reports with their associated tags and structured data will be imported for you to use.
Please note that this module is not part of the open-source version and is installed as an external module. If you are interested in this module, please contact antoine@docintel.org.
Installation
To install the module, follow these steps:
- Copy the received public key to
$DOCINTEL_DATA/modules/public.pem
. - Download the archive and extract its contents.
- Copy the contents of the archive to
$DOCINTEL_DATA/modules/mandiant
. - Copy the licence file to
$DOCINTEL_DATA/modules/mandiant/licence.txt
. - Restart the application.
- Go to Ingestion > Collectors
- Click Install
- Select
mandiant.threat-intel-reports
in the collector dropdown. Refer to Collector for more information about how to configure a collector. - Click Install
- Enter your API key and secret.
- Click save