Playbook All on Content Hub
Threat feed ingestion template
Fetch-and-create skeleton for bulk-ingesting threat intel indicators.
@ftnt-dspilleMaintainer v1.0.0 Platform 7.4.0+ Published Sep 22, 2026
Download JSON · 15 KB
threat-feed-ingestion-template.json
sha256:cddafd672865b243dec9912a81411dc866e14486ae6a0e13fcf2f5b342910651
Sanitized by the pipeline and shipped inactive. Follow the before turning it on.
A starting point for threat-intel feed connectors: fetch indicators, map them, then hand them to the bulk-feed ingestion step. Replace the placeholder steps with your feed's operations.
Something wrong with this item? Sign in to report