
Contents
Preface 5
About this guide .................................. 5
Audience .................................. 5
Conventions ................................. 5
Find product documentation ..............................6
1 Overview 7
Benefits of Threat Intelligence Exchange .........................7
Threat Intelligence Exchange components ........................ 8
Threat Intelligence Exchange module ....................... 8
Threat Intelligence Exchange server ....................... 9
Data Exchange Layer ..............................9
How Threat Intelligence Exchange works ........................ 11
How a reputation is determined ............................11
2 Using Threat Intelligence Exchange 13
Getting started with Threat Intelligence Exchange .................... 13
Building file prevalence and observing ...................... 13
Monitoring and making adjustments ....................... 13
Submitting files for further analysis ....................... 14
Blocking or allowing files and certificates ........................ 15
Create a Threat Intelligence Exchange module policy ................ 16
Changing default threat reputations .......................... 16
Change default threat reputations ........................16
Change the reputation of a file or certificate ....................17
Import reputations .............................. 18
Change reputations using the McAfee ePO Web API .................19
Determine where a file ran in your environment ..................... 19
Monitoring events ................................. 20
Viewing recent events .............................20
View details about recent threats ........................ 21
Responding to events .............................22
Setting a system's health status .........................22
Managing Data Exchange Layer brokers .........................23
Data Exchange Layer components ........................23
Add or update brokers ............................ 23
Add brokers to a DMZ .............................23
3 Reporting 25
Viewing reports .................................. 25
Access reports ................................25
Index 27
McAfee Threat Intelligence Exchange 1.0.0 Product Guide
3
Comentarios a estos manuales