Intel Submissions is the process of adding or sharing new threat intelligence data such as, IoCs, tactics, techniques, procedures, threat actors, malware signatures, or vulnerability details for analysis, correlation, and distribution. This helps to detect, investigate, and respond to threats more effectively.
You can submit suspicious IOCs. These IOCs will be shared with the community post verification.
The Submissions by Users tab helps you to view and analyze all the incoming intel. You can view the submitted intel details, their severity (critical, high, medium, low) and filter the intel by specific date range that is last 1 day, last 7 days, last 1 month, last 3 months, and last 1 year.
Adding New Intel
To add a new intel, follow these steps:
- On the Seqrite Threat Intelligence portal, click Submissions by Users in the left pane.
- On the Submissions by Users page, click + Add Intel.
- Enter Incident Basic Details, that are Title, Incident Date, Intel Category and Description, and click Add IOC Manually.
- Enter IOC details that are, IOC Type, IOC Classification, IOC Volume, Severity, Deviec Type/Source, Adversary Name, Adversary Type, Tag, and click Add.
- If you want to review the intel before submission, click Save else click Submit.
The Add Intel page is displayed.
This provision is also available to Org/Regulated Entity Admins as well.
Note: The Seqrite Admin will approve the submitted intel.
Viewing the Intel Submissions
You can view the intel submissions details such as severity (Critical, High, Medium, Low) highlighted with the color codes, Sub ID (Submission ID), Intel ID, title, reported on, approved on, and the status in the tabular format.
To view the details of each intel, follow these steps:
- On the Seqrite Threat Intelligence portal, click Submissions by Users in the left pane.
- On the Submissions by Users page, select the intel and click the > icon.
- The intel submission details page displays the following details:
- Primary Information: For example, APT Category (Name, Inel Category, Incident Date, Description)
- To view IOC details, click the intel.
The IOC Details page appears along with the intel status that is Approved, Rejected or Pending.
Filtering the Intel Submissions List
You can filter the intel submissions list to refine results based on submission ID, intel ID, submission title, reported on, approved on, and submission status.
To filter the intel submissions list, follow these steps:
- On the Seqrite Threat Intelligence portal, click Submissions by Users in the left pane.
- On the Submissions by Users page click
. - Enter the details that are, submission ID, intel ID, submission title, reported on, approved on, and submission status and then click Apply.
The system displays filtered data.
Exporting Intel Submissions as a CSV
You can download all the intel submissions currently visible on the page in the CSV format.
To export/download intel submissions, follow these steps:
- On the Seqrite Threat Intelligence porta, click Submissions by Users in the left pane.
- On the Submissions by Users page click Export CSV.