Sign inSign up

lumutools/cisco-firepower-threat-feeder

By lumutools

•Updated about 4 years ago

Cisco Firepower Threat Feeder

Image
0

1.0K

lumutools/cisco-firepower-threat-feeder repository overview

⁠Lumu - Firepower Threat Defense Integration

Lumu Defender offers a framework to help you leverage Lumu’s integrations with your existing cybersecurity stack, including Security Information and Event Management (SIEM); Security Orchestration, Automation, and Response (SOAR); Endpoint Detection and Response (EDR); incident response systems; and more.

The Lumu Defender Firepower Threat Defense Out-of-the-box integration allows you to configure Cisco Firepower to receive and block adversaries detected by Lumu and improve the detection & response capabilities of your organization; however, this type of integration is limited to deployments managed through the Cisco® Secure Firewall Management Center (CSFMC). See more at: Lumu docs⁠

This project provides you with the ability to integrate your Cisco Firepower Firewalls with Lumu in the absence of CSFMC.

⁠Getting Started

This guide shows you how to use this project to feed your Cisco Firepower Firewalls with Lumu's confirmed compromises.

The source code of this project is also available at Lumu in Bitbucket⁠

⁠Requirements

Before trying to run this project, be sure to properly set up the Lumu Defender Firepower Threat Defense Out-of-the-box integration. See more at: Lumu docs⁠

In order to run this project you'll need docker installed in the machine you intend to use it at.

⁠Usage
  1. Prepare the container (replace VALUE with proper values):
 docker create \
 -e INTEGRATION_UUID=VALUE \
 -e HOST_URL=VALUE \
 -e USERNAME=VALUE \
 -e PASSWORD=VALUE \
 -e VERIFY_TLS=VALUE \
 -e MAX_REQUEST_ATTEMPTS=VALUE \
 -e FREQUENCY=VALUE \
 --restart unless-stopped \
 --name lumu-cisco-firepower-threat-feeder \
 --log-opt tag=lumu-cisco-firepower-threat-feeder \
 --log-opt max-size=100m \
 --log-opt max-file=1 \
 lumutools/cisco-firepower-threat-feeder:latest
  1. Run it:
docker start lumu-cisco-firepower-threat-feeder
⁠Parameters
  • INTEGRATION_UUID - Lumu integration uuid
  • HOST_URL - Firepower Threat Defense url
  • USERNAME - Username to login in Firepower Threat Defense
  • PASSWORD - Password to login in Firepower Threat Defense
  • VERIFY_TLS - No Verify TLS -v or Verify TLS -V. Use -v if your Firewall is using a self-signed certificate.
  • MAX_REQUEST_ATTEMPTS - Max number retries this script will attempt if requests to Cisco Firepower are failing.
  • FREQUENCY - Polling frequency in minutes (1-30). How often to check for updates.
⁠General Recommendations

For the proper functioning of the integration, follow these recommendations:

  • If you need to create a urlobject, do not use the Lumu prefix in the name. We assign this prefix to threats detected by Lumu.
  • If you need to allow access to a URL that is being blocked, please add it to the whitelist.
  • Do not delete any of our detections, doing so could prevent the integration from working properly.
  • When using the Docker image, do not stop the container. This will cause the synchronization process to restart from scratch.
  • When using the Docker image, a frequency between 20 to 30 minutes is recommended.

⁠Find more about us

Tag summary

Content type

Image

Digest

sha256:c9b986c75…

Size

21 MB

Last updated

about 4 years ago

docker pull lumutools/cisco-firepower-threat-feeder