Infoblox-microsite.png
Infoblox Guide

Infoblox ActiveTrust Threat Intelligence Data Exchange (TIDE) and Dossier integration with Splunk Enterprise Security

Infoblox Threat Intelligence Data Exchange (TIDE) for ActiveTrust® uses highly accurate machine-readable threat intelligence data via a flexible Threat Intelligence Data Exchange (TIDE) to aggregate, curate and enable distribution of data across a broad range of infrastructure. ActiveTrust TIDE provides an API access to active indicators of compromise (IOC) such as domain names, hostnames and IP-addresses. The indicators can have an expiration date and time. This implementation aims at integrating the Threat Intelligence Data with the Splunk Enterprise Security providing the ability to block access to malicious domains and IP addresses as well as provide a mechanism to enrich investigations through dynamic checks.

Download the Resource