Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 
 

Configure SecIntel Feeds in Juniper ATP Cloud Portal

You can configure SecIntel feeds to get curated and verified threat intelligence from multiple sources. These SecIntel feeds are pushed to your devices, which then block C&C communications at line rate and subscribe to the SecIntel’s infected host feed.

You can configure the following SecIntel feeds for integration with Juniper ATP Cloud:

  • Third Party Threat Feeds—IP and URL threat feeds

  • Dynamic Address Group Feeds—Juniper-provided and third-party DAG feeds.

SecIntel supports 32 C&C feeds. Four of the C&C feeds are predefined Juniper threat feeds:

  • cc_ip

  • cc_url

  • cc_ipv6

  • cc_cert_sha1

The remaining 28 feeds can be configured as third-party or custom C&C feeds added through OpenAPI.

To configure SecIntel feeds in the Juniper ATP Cloud portal:

  1. Log in to Juniper ATP Cloud portal.
  2. Click Configure > Feeds Configuration > SecIntel Feeds.
    The SecIntel Feeds page is displayed.
  3. For the Juniper Threat Feeds, select any of the C&C categories based on the threats you want to detect and mitigate:
    • Malicious—By default, the Malicious category is selected to provide the standard feeds. This category includes 14 subcategories, such as malware C&C servers, known infected bots, known spam sources, and distributed denial of service (DDoS) sources.

    • Inbound Block (Routers)—Select this category to block incoming traffic on edge devices such as routers from known infected bots, spam sources, DDoS sources, and other malicious sources. The Inbound Block (Routers) category includes six subcategories.

    • Suspicious—Select this category if the threats are suspicious gaming websites, chat servers, proxy hosts, VPN servers, and so on. The Suspicious category includes 17 subcategories.

    Key Considerations:

    • Keep the Malicious category selected to receive the default feeds. If you need additional feeds, select the Inbound Block (Routers) and Suspicious categories.

    • The C&C category selection affects only the Juniper-managed C&C feeds, such as cc_ip_data and cc_url_data.

    • You can view all the subcategories in the portal but you cannot select them.

    The selected C&C categories are then automatically pushed to the device from Juniper ATP Cloud.

  4. On the device CLI, enter the command show services security-intelligence category summary to verify that the C&C categories are pushed to the device.

    Here's a sample output for the command:

    In the CLI command output, the Version and Objects number fields indicate the C&C feeds that are downloaded by the device.

    • If the device downloads only selected C&C categories, the Version field includes a category-specific identifier, such as 20260529.9.78ed4f57f9. The Objects number field shows only the indicators from the selected categories.

    • If all C&C categories are selected and downloaded, the Version field uses the standard format, such as 20260529.9. The Objects number field shows a higher count because the device downloads the entire C&C feeds.

    If you change the C&C category in the portal, the device might take a few minutes to download the updated feeds. After the download completes, the CLI command output shows the updated feeds.

  5. To configure Third Party Threat Feeds and Dynamic Address Group Feeds, select the toggle to enable each feed as per the guidelines provided in Table 1.
  6. On the device CLI, enter these commands to configure a SecIntel policy for the enabled C&C and third-party threat feeds:
  7. Enter the these commands to configure a Security Policy and add the SecIntel policy to the security policy:
Table 1: Third Party Threat and DAG Feeds

Field

Guidelines

Predefined Cloud Feed Name

Third Party Threat Feeds

IP Threat Feeds

DShield

Click the toggle button to enable DShield feeds as third-party feeds.

cc_ip_dhield

Block List

Click the toggle button to enable block list feeds as third-party feeds.

cc_ip_blocklist

Tor

Click the toggle button to enable tor feeds as third-party feeds.

cc_ip_tor

Threatfox IP

Click the toggle button to enable Threatfox feeds as third-party feeds.

cc_ip_threatfox

Feodo Tracker

Click the toggle button to enable Feodo feeds as third-party feeds.

cc_ip_feodotracker

For more information about third-party threat feeds, see Third-Party Threat Feeds.

URL Threat Feeds

Threatfox URL

Click the toggle button to enable Threatfox feed as third-party feeds. ThreatFox is a free platform from abuse.ch with the goal of sharing indicators of compromise (IoC) associated with malware with the infosec community, antivirus vendors and threat intelligence providers. The IOC can be an IP address, domain name, or URL.

cc_url_threatfox

Open Phish

Click the toggle button to enable OpenPhish feed as third-party feeds. OpenPhish is a fully automated self-contained platform for phishing intelligence. It identifies phishing sites and performs intelligence analysis in real time without human intervention and without using any external resources, such as blocklists. For malware inspection, SecIntel will analyze traffic using URLs in this feed.

cc_url_openphish

URLhaus URL Threat Feed

Click the toggle button to enable URLhaus feed as third-party feeds. URLhaus is a threat intelligence feed that shares malicious URLs that are used for malware distribution.

cc_url_urlhaus

Domain Threat Feeds

Threatfox Domains

Click the toggle button to enable Threatfox feed as third-party feeds.

cc_domain_threatfox

Dynamic Address Group Feeds

Third Party DAG Feeds

Third-party DAG feeds require specific configuration parameters, including a predefined cloud feed name. For a sample configuration, see Example: Enable Microsoft Office 365 Feeds. You can use the same procedure to configure and enable other supported third-party DAG feeds with the appropriate feed-specific values.

paypal

Click the toggle button to enable feeds from Paypal.

ipfilter_paypal

amazonaws

Click the toggle button to enable feeds from AWS.

You can filter and view the DAG feeds from AWS regions and services that are relevant to you. To configure DAG filters for AWS feed, click Configure, and follow the instructions in Add and Manage DAG Filters.

ipfilter_amazonaws

zoom

Click the toggle button to enable feeds from Zoom.

ipfilter_zoom

google

Click the toggle button to enable feeds from Google.

ipfilter_google

okta

Click the toggle button to enable feeds from Okta.

ipfilter_okta

atlassian

Click the toggle button to enable feeds from Atlassian.

ipfilter_atlassian

oracleoci

Click the toggle button to enable feeds from Oracle oci.

ipfilter_oracleoci

cloudflare

Click the toggle button to enable feeds from Cloudflare.

ipfilter_cloudflare

zpa zscaler

Click the toggle button to enable feeds from Zscaler Private Access (ZPA). The ZPA service provides secure access to the applications and services within your organization.

ipfilter_zscaler_zpa

facebook

Click the toggle button to enable feeds from Facebook.

ipfilter_facebook

microsoftazure

Click the toggle button to enable feeds from Microsoft Azure.

You can filter and view the DAG feeds from Azure regions and services that are relevant to you. To configure DAG filter for Azure feeds, click Configure, and follow the instructions in Add and Manage DAG Filters.

ipfilter_microsoftazure

office365

Click the toggle button to enable office365 IP filter feed as a third party feed. The office365 IP filter feed is an up-to-date list of published IP addresses for Office 365 service endpoints which you can use in security policies.

ipfilter_office365

zscaler

Click the toggle button to enable feeds from Zscaler.

ipfilter_zscaler

You've configured the SecIntel feeds in Juniper ATP Cloud and enabled the required threat intelligence sources for your deployment. Selected Juniper threat feed categories, third‑party threat feeds, and DAG feeds automatically synchronize with your devices. You can use the feeds to identify, monitor, and block malicious communications based on your security policies.

Example: Enable Microsoft Office 365 Feeds

Third-party DAG feeds require certain configuration parameters, including a predefined cloud feed name.

To enable Microsoft Office 365 feeds:

  1. Select the Using the office365 Feed check box in Juniper ATP Cloud to push Microsoft Office 365 services endpoint IP addresses to the SRX Series Firewall. The office365 feed works differently from other feeds on this page and requires specific configuration parameters, including a predefined name ipfilter_office365.

  2. After you select the check box, create a dynamic address object on the SRX Series Firewall that refers to the ipfilter_office365 feed:

    A security policy can then reference the dynamic address name (office365 in this example) in the source or destination address.

    A sample security policy is as follows:

  3. Use the CLI command show services security-intelligence category summary to verify the office365 feed has been pushed to the SRX Series Firewall. Update Status should display Store succeeded..

  4. Use the CLI command show security dynamic-address category-name IPFilter to show all the individual feeds under IPFILTER.

You've enabled the Microsoft Office 365 feed and verified that the feed data is available on the SRX Series Firewall. You can now use the ipfilter_office365 dynamic address object in security policies to manage traffic for Microsoft Office 365 services.

Third-Party Threat Feeds

If an enabled third‑party threat feed detects malware, the event appears under Monitor > Threat Sources with a threat level of 10.

On the enrolled SRX Series Firewalls, you can configure policies with the permit or block actions for each feed. The C&C and Infected Host feeds require a SecIntel policy enabled on the SRX Series Firewall.

Third-party threat feeds are updated every 24 hours.

Warning:
  • Third-party threat feeds are open-source, and the Juniper ATP Cloud administrator is responsible for determining the accuracy of each feed. Juniper Networks does not investigate false positives generated by the third-party threat feeds.

  • Configured SRX Series Firewall policies will block malicious IP addresses based on the enabled third-party threat feeds. However, any event from the feeds do not affect the host threat scores. Only events from the Juniper threat feeds affect the host threat scores.