Uploading Indicators

Updated 1 month ago by Elvis Hovor

You can upload and submit Indicators to TruSTAR Station using any of the following procedures:

  • Using the TruSTAR API
  • Using TruSTAR Station to a simple list of Indicators
  • Using TruSTAR Station to upload a list of Indicators and related information.

Uploading with the API

Follow the API guide: https://docs.trustar.co/api/v13/indicators/submit_indicators.html

Uploading a Simple List

This process uploads a simple list of Indicators, without any contextual information attached.

  1. Click Submit in the top navigation bar.
  2. Click Submit Indicator on the dropdown menu.
  3. Click the box listing the format you will use to upload the list.
    1. Upload IOC Spreadsheet (.csv or .xls file formats)
    2. Upload file (any of these extensions: DOC, PDF, TXT, JSON, XML)
    3. Add text (freeform copy and paste)
  4. Upload the data by following the instructions on the Upload Data screen.
  5. Click Next.
  6. Select the enclaves where you want to store the Indicators. You can also add tags to the Indicators in this step.
  7. Click Submit.

TruSTAR will email you after the list is processed and the new data is available for analysis and investigation. The email will show how many Indicators were processed during the import. You will be able to go to the Explore view and start browsing through the list and apply various Enclave and Tag filters.

Uploading a List with Context Information

If you have been collecting historical context for Indicators, such as first seen, last seen, sightings etc., you can bring that information into TruSTAR as part of the upload.

  1. Create an XLS or CSV file with six columns with titles that exactly match the bold text in each bullet below:
  • Value: Indicator
  • Source: text indicating where this Indicator was collected from
  • Notes: text of any notes to be added to the Indicator
  • First Seen: must be a numeric value
  • Last Seen: must be a numeric value
  • Sightings: count of how many times the Indicator has been observed in a specific campaign, TTP or threat activity. Must be a numeric value.
  • Tags: text that will label the Indicator with a tag. To apply multiple tags separate them by adding additional columns (i.e Tag_1, Tag_2, etc.)

See the example below for exact formatting requirements.

It is not necessary to provide all this information to use this feature. You must have all the columns named as shows, but any empty fields below that are ignored during the upload process.
  1. Enter your data in the rows below the title row and then save the file.
  2. Click Submit in the top navigation bar.
  3. Click Submit Indicator on the dropdown menu.
  4. Select the Upload IOC Spreadsheet option.
  5. Drag and drop the file into the dialog box.

If the file submission is invalid, you will be asked to correct the file. Check that the file meets these conditions:

  • Contains the Value column header.
  • Contains between 1 and 10,000 rows of data.
  • Values in the First Seen, Last Seen, and Sightings columns must be numbers.
  1. Select the enclaves you want to upload to.
    OPTIONAL: Add any tags you want associated with all of the Indicators.
  2. Click Submit.

You will be sent an email notification after the entire list is processed and is available for analysis and investigation. The email will have the details of how many Indicators were processed. You can then go to the Explore view and start browsing through the Indicators and apply various Enclave and Tag filters.

FAQ: Indicator Uploading


How Did We Do?