Feeds
The Feeds tab (Intelligence › Feeds) shows where your threat intel comes from. It lists your organization's private TAXII and MISP feeds and the shared feeds that Huntbase provides, with health, volume and matches for each. It's also where you choose how each feed is matched against your telemetry.
Feeds is part of Intelligence, which is in beta. Access is by request, so it may not be enabled for your organization.
Your feeds and shared feeds
The page has two sections:
- Your feeds: private TAXII 2.1 and MISP feeds that your organization has connected. Only your organization can read their indicators, and they are never shared with anyone else.
- Shared feeds: feeds that Huntbase fetches once and makes available to every organization, such as reputation blocklists and MITRE ATT&CK. You decide whether and how your organization matches against them.
Watch lists are private sources too, but you manage them from Indicators.
Each feed shows:
- its kind (TAXII, MISP or Bulk) and its health;
- the number of active indicators, how many were added in the last 7 days, and how many matched your telemetry in the last 7 days;
- when it last synced successfully;
- a one-line summary of your subscription, for example Alerting · conf ≥ 50 · 30-day retro-hunt.
The line above the sections counts your feeds and how many need attention.
Health
| Health | Meaning |
|---|---|
| Healthy | The last run succeeded on schedule. |
| Stale | No successful run for more than twice the poll interval, or for more than 24 hours for a bulk feed. |
| Failing | The last run failed. The error is shown on the row and at the top of the feed's details. |
| Paused | The feed isn't being polled. |
| Never run | The feed hasn't been polled yet. |
Add a feed
TAXII and MISP feeds are connections, because that's where their credentials and health checks live. A feed you add appears both here and in Connections.
- Select Add feed and choose TAXII 2.1 feed or MISP feed.
- The connection setup opens with the product already chosen. Enter the server details and credentials, then create and check the connection. See TAXII 2.1 Feed for what to ask your feed provider for.
- When you finish, you're taken back to Feeds. The first poll runs on the feed's schedule, or straight away if you select Sync now.
Your organization is subscribed to a new private feed straight away, with a 30-day retro-hunt.
Sync now
Private TAXII and MISP feeds have a Sync now button, on the row and in the feed's details. It asks Huntbase to poll the feed straight away instead of waiting for the next scheduled run.
The sync runs in the background. While it runs, the button shows its progress, for example Queued… or Syncing · 1,200. When it finishes you get a message with the number of indicators added and updated, and the feed's numbers and run history refresh. If a sync is already running, Huntbase tells you so and follows that run instead of starting a second one.
A sync picks up where the last successful one stopped, so running it again only fetches what's new. A very large feed may finish as Partial; the next run continues from where it stopped.
Shared feeds are polled by Huntbase on their own schedule, so they don't have a Sync now button. Syncing needs permission to manage watchers.
Feed details
Select a feed to open its details on the right.
- Manage connection (private feeds): opens the feed's connection, where you change the server details or rotate its credentials.
- Numbers: active indicators, indicators added and matches in the last 7 days, the last successful sync, the poll interval, the source reliability (A to F) and the default TLP.
- Your subscription: see below.
- Indicator types: how the feed's active indicators split across IPs, domains, URLs, hashes and other types.
- Overlap with other feeds: the share of this feed's indicators that another feed also has. Huntbase works this out nightly, so it's empty for a new feed.
- Runs: each poll, newest first, with when it started, what started it (Scheduled or Manual), its status, the number of indicators added, updated and retired (expired or revoked), errors and how long it took. Hover over a failed run's status to read the error. Load more runs shows older runs.
Your subscription
The subscription controls how your organization uses a feed. It's your organization's own setting, so changing it doesn't affect anyone else. Changing it needs permission to manage watchers; without that, the form is read-only.
| Setting | What it does |
|---|---|
| Match against my telemetry | Off keeps the feed's indicators searchable in Indicators but never matches them. |
| Minimum confidence | Indicators below this confidence (0 to 100) are kept but never matched. Raise it for a noisy feed. |
| On a match | Alert records a sighting and raises a finding through the Threat intel indicator matched watcher. Sighting only records the sighting on the indicator without a finding. Off doesn't match. |
| Retro-hunt new intel | When the feed brings new indicators, hunt for them across this many days of your telemetry (Off, or 7 to 90 days). |
Until you change anything, a shared feed uses its default subscription, and the form says so. Select Save subscription to keep your changes, or Reset to discard them.