---
title: "Infoblox Threat Intelligence Feed instance"
canonical: "https://docs.infoblox.com/space/DeploymentGuideTDDDIforCortexXSOAR/1810858104/Infoblox%20Threat%20Intelligence%20Feed%20instance"
format: markdown
---
## **Purpose**

To enable ingestion of threat intelligence indicators from Infoblox Cloud into Cortex for proactive detection and automated enrichment.

This integration allows Cortex to retrieve threat indicators such as malicious domains, IPs, URLs, and hashes directly from Infoblox Threat Intelligence Feed, helping analysts correlate incidents and automate remediation workflows.

## **Key Goals**

- Automate the retrieval and normalization of Infoblox threat data.
- Enrich incidents with threat classes, properties, and risk metrics.
- Correlate indicators across DNS Security and SOC Insights modules.
- Empower SOCs to proactively block malicious domains and IPs.

## **Configuration Steps**

1. In Cortex, navigate to  
**Settings & Info → Integrations → Instances**.
2. Search for **Infoblox Threat Intelligence Feed (Partner Contribution)** (installed from Marketplace).
3. Click **Add Instance**.
4. Enter an identifiable name such as **Infoblox Threat Intelligence Feed – Instance**.
5. Provide the **Service API Key** generated from the Infoblox Cloud Portal under *Service API Keys*. *(Mandatory)*
6. (Optional) Enable **Use system proxy** or **Trust any certificate (not secure)** if required by your environment.
7. Expand the **Collect** section and ensure **Fetches indicators** is checked.
8. Choose indicator types (e.g., *IP, HOST, URL, EMAIL, HASH*).
9. Configure optional parameters such as:
  1. **First Fetch Time** – e.g., `1 hour`
  2. **Max Indicators per Fetch** – e.g., `1000`
  3. **Feed Fetch Interval** – e.g., `30 minutes`
  4. **Indicator Reputation** – typically set to *Suspicious*
  5. **Source Reliability** – choose *B – Usually reliable* or adjust per your policy
  6. **Traffic Light Protocol Color** – e.g., *AMBER*
10. Click **Test Connectivity** to validate the connection with Infoblox Cloud.
  1. A success message confirms that the instance can fetch indicators.
  2. If it fails, verify the API key, proxy configuration, and outbound connectivity.
11. Once verified, click **Save & Exit**.

## Capabilities

- Retrieves threat indicators (IPs, domains, URLs, hashes, etc.) from Infoblox Cloud.
- Supports filtering by indicator type, reputation, and data provider.
- Enables Cortex to automatically enrich incidents with Infoblox intelligence context.
- Allows playbooks to consume threat feeds for automated detection and response.
- Improves threat visibility and correlation across SOC operations.

> ℹ️ Refer to the **Help** section on the right-hand side of the Cortex configuration page for parameter descriptions, valid indicator types, and guidance on customizing fetch intervals or filters.