Zero-day vulnerability tracking
Learn how to analyze RSS Feeds coming into the system.
Before you begin
Role required:
- System Administrator (view, create or edit)
- sn_sec_tisc.admin (view)
About this task
Whenever a new RSS Feed is created into the system, and it has a mention of ‘Zero Day’ in either title or description.
Procedure
Navigate to All > Threat Intelligence Security Center > Administration.
Select Automated Flows.
Select Zero-day vulnerability tracking link to view the respective rule details in the flow designer.
View the flow designer action for the following trigger:
RSS Feed Created where (Title contains zero day, or Description contains zero day, or Title contains zero_day, or Description contains zero_day, or Title contains zero-day, or Description contains zero-day)If the observable is an IPv4 or IPv6 address and it falls within an allowed CIDR range, then:
Create a case for TISC Team, along with a remediation task for VR Team.
Notify the concerned TISC Teams and VR Teams.
Parent Topic:Working with automated flows
Related topics
Automated sharing of high-risk IOC's with trusted partners
Automatically add threat intelligence to a TAXII collection
Create vulnerability assessment for zero day
Analyze, assess, and disseminate observables
Analyze and assess threat IoC’s
Vulnerability Management Support