Uploading IOCs

Updated 1 week ago by Elvis Hovor

You can upload and submit IOCs to TruSTAR Station using any of the following procedures:

  • Using the TruSTAR API
  • Using TruSTAR Station to a simple list of IOCs
  • Using TruSTAR Station to upload a list of IOCs and related information.

Uploading with the API

Follow the API guide: https://docs.trustar.co/api/v13/indicators/submit_indicators.html

Uploading a Simple IOC List

This process uploads a simple list of IOCs, without any contextual information attached.

  1. Click Submit in the top navigation bar.
  2. Click Submit Indicator on the dropdown menu.
  3. Click the box listing the format you will use to upload the IOC list.
    1. Upload IOC Spreadsheet (.csv or .xls file formats)
    2. Upload file (any of these extensions: DOC, PDF, TXT, JSON, XML)
    3. Add text (freeform copy and paste)
  4. Upload the data by following the instructions on the Upload Data screen.
  5. Click Next.
  6. Select the enclaves where you want to store the IOCs. You can also add tags to the IOCs in this step.
  7. Click Submit.

TruSTAR will email you after the IOC list is processed and the new data is available for analysis and investigation. The email will show how many IOCs were processed during the import. You will be able to go to the Explore view and start browsing through the IOCs and apply various Enclave and Tag filters.

Uploading IOCs with Context Information

If you have been collecting historical context for IOCs, such as first seen, last seen, sightings etc., you can bring that information into TruSTAR as part of the IOC import.

  1. Create an XLS or CSV file with six columns with titles that exactly match the bold text in each bullet below:
  • Value: IOC
  • Source: text indicating where this IOC was collected from
  • Notes: text of any notes to be added for the IOC
  • First Seen: must be a numeric value
  • Last Seen: must be a numeric value
  • Sightings: count of how many times the IOC has been observed in a specific campaign, TTP or threat activity. Must be a numeric value.
  • Tags: text that will label the indicator with a tag. To apply multiple tags separate them by adding additional columns (i.e Tag_1, Tag_2, etc.)

See the example below for exact formatting requirements.

It is not necessary to have all this information to use this upload feature. You can use it even if you only have information for one of them e.g. First Seen Time.
  1. Enter your data in the rows below the title row and then save the file.
  2. Click Submit in the top navigation bar.
  3. Click Submit Indicator on the dropdown menu.
  4. Select the Upload IOC Spreadsheet option.
  5. Drag and drop the IOC file into the dialog box.

If the file submission is invalid, you will be asked to correct the file. Check that the file meets these conditions:

  • Contains the Value column header.
  • Contains between 1 and 10,000 rows of data.
  • Values in the First Seen, Last Seen, and Sightings columns must be numbers.
  1. Select the enclaves you want to upload to.
    OPTIONAL: Add any tags you want associated with all of the IOCs.
  2. Click Submit.

You will be sent an email notification after all the IOCs are processed and are available for analysis and investigation. The email will have the details of how many IOCs were processed. You will be able to go to the Explore view and start browsing through the IOCs and apply various Enclave and Tag filters.


How Did We Do?