Skip to content
Playbook All on Content Hub

Threat feed ingestion template

Fetch-and-create skeleton for bulk-ingesting threat intel indicators.

@ftnt-dspilleMaintainer v1.0.0 Platform 7.4.0+ Published Sep 22, 2026
Download JSON · 15 KB

threat-feed-ingestion-template.json

sha256:cddafd672865b243dec9912a81411dc866e14486ae6a0e13fcf2f5b342910651

Sanitized by the pipeline and shipped inactive. Follow the before turning it on.

A starting point for threat-intel feed connectors: fetch indicators, map them, then hand them to the bulk-feed ingestion step. Replace the placeholder steps with your feed's operations.

Something wrong with this item? Sign in to report

Report a problem

Sensitive data, copied content, broken imports, anything that shouldn't be here.

At least 10 characters. Please don't paste the sensitive value itself.0/1000