Configure Anomali STAXX

Do this procedure to configure the Anomali STAXX, a free TAXII/STIX solution, for integration with the Nozomi Networks TAXII server, including setting descriptions, uniform resource locators (URLs), and authentication details.

  1. Download Anomali STAXX from the Anomali website.
  2. To install the downloaded open virtual appliance (OVA) file, follow the Anomali instructions.
  3. Launch Anomali STAXX.
  4. Select Add New Site.
    A dialog shows.
  5. In the Description field, enter a description.

  6. In the Discovery URL field, enter the Discovery uniform resource locator (URL): https://ti-taxii.nws.nozominetworks.io/taxii/
  7. Select the Basic Authentication checkbox.
  8. In the Username field, enter your username.
  9. In the Password field, enter your password.
  10. Do not select the SSL Two-Way Certificate checkbox.
  11. Select Add Site.
    The site will be added.
  12. In the section on the right, select Discover.
  13. Select Enable for each item as necessary.
  14. To select the time range to poll indicators from, select Edit for the applicable collection.
    In order to receive historical indicators, this value should be high for the initial poll. You can then decrease it based on how often the server will be polled. For example, if polling daily, only poll for indicators that have been added within the last 24 hours.

  15. To poll indicators, select Poll Now.

    Note: This can take some minutes depending on how large a collection is.
    Once this process completes, the number of Last Poll Observables will show a value.

The indicators can be accessed from the Dashboard menu.