Cisco Firepower Threat Feeder
1.0K
Lumu Defender offers a framework to help you leverage Lumu’s integrations with your existing cybersecurity stack, including Security Information and Event Management (SIEM); Security Orchestration, Automation, and Response (SOAR); Endpoint Detection and Response (EDR); incident response systems; and more.
The Lumu Defender Firepower Threat Defense Out-of-the-box integration allows you to configure Cisco Firepower to receive and block adversaries detected by Lumu and improve the detection & response capabilities of your organization; however, this type of integration is limited to deployments managed through the Cisco® Secure Firewall Management Center (CSFMC). See more at: Lumu docs
This project provides you with the ability to integrate your Cisco Firepower Firewalls with Lumu in the absence of CSFMC.
This guide shows you how to use this project to feed your Cisco Firepower Firewalls with Lumu's confirmed compromises.
The source code of this project is also available at Lumu in Bitbucket
Before trying to run this project, be sure to properly set up the Lumu Defender Firepower Threat Defense Out-of-the-box integration. See more at: Lumu docs
In order to run this project you'll need docker installed in the machine you intend to use it at.
docker create \
-e INTEGRATION_UUID=VALUE \
-e HOST_URL=VALUE \
-e USERNAME=VALUE \
-e PASSWORD=VALUE \
-e VERIFY_TLS=VALUE \
-e MAX_REQUEST_ATTEMPTS=VALUE \
-e FREQUENCY=VALUE \
--restart unless-stopped \
--name lumu-cisco-firepower-threat-feeder \
--log-opt tag=lumu-cisco-firepower-threat-feeder \
--log-opt max-size=100m \
--log-opt max-file=1 \
lumutools/cisco-firepower-threat-feeder:latest
docker start lumu-cisco-firepower-threat-feeder
INTEGRATION_UUID - Lumu integration uuidHOST_URL - Firepower Threat Defense urlUSERNAME - Username to login in Firepower Threat DefensePASSWORD - Password to login in Firepower Threat DefenseVERIFY_TLS - No Verify TLS -v or Verify TLS -V. Use -v if your Firewall is using a self-signed certificate.MAX_REQUEST_ATTEMPTS - Max number retries this script will attempt if requests to Cisco Firepower are failing.FREQUENCY - Polling frequency in minutes (1-30). How often to check for updates.For the proper functioning of the integration, follow these recommendations:
Content type
Image
Digest
sha256:c9b986c75…
Size
21 MB
Last updated
about 4 years ago
docker pull lumutools/cisco-firepower-threat-feeder