Mallory IOC Sync
Pulls the Mallory observables that meet a malicious-opinion policy I set and writes them, with expiry, into the lookup, watchlist, or reference list your detection rules already read.
What this agent does
This agent keeps a detection list current from Mallory. On a schedule it reads the observables updated in the window and their opinions, keeps the ones that meet a verdict and confidence policy I set, and writes them into one named list in the SIEM: a Splunk lookup, a Microsoft Sentinel watchlist, an Elastic Security value list, a Google SecOps reference list, or a Datadog reference table. Each entry carries the source, the verdict, the confidence, and an expiry. It removes entries past their expiry and never touches a prevention or blocking control.
The challenge
Detection rules that match on indicators miss whatever the list lacks. The list goes stale the week after someone loads it. Loading it by hand means exporting a feed, reformatting it, and uploading, so it happens once a quarter. Indicators that expired a year ago still fire, and the ones from last night's campaign are not there. Nobody knows which feed put which entry in the list.
The solution
The agent does the pull and the load on a schedule, with one policy for what qualifies and one list per SIEM that the team's rules reference. It stamps every entry with where it came from and when it expires, and it ages entries out. It writes only to that named list and never to a firewall, proxy, or endpoint block policy. Provides a detection list that is current to the last run and auditable to its source.
Workflow
- 01
Pull updates
Load the first run from the full IOC export, read each incremental IOC export on later runs, and page the API only when an export is missing.
- 02
Apply the policy
Keep observables that meet the verdict, confidence, source, age, and type rules I set, and drop the rest with the reason.
- 03
Write the list
Add new entries and refresh existing ones in the named list, each with source, verdict, confidence, first seen, and expiry.
- 04
Expire
Remove entries past their expiry, and entries whose observable has a benign opinion and no malicious opinion in the last 30 days.
- 05
Report
Report what was added, refreshed, expired, excluded, and failed.
Agent template
# Mallory IOC Sync
## Measurable outcomes
The named list in the SIEM holds every Mallory observable that met the policy in the window and no entry past its expiry. Track the added, refreshed, expired, excluded, and failed counts on every run, and the list size by type.
## Procedure
Run on the schedule I set, hourly by default. Load the first run from the full IOC export. On later runs, read each incremental IOC export generated since the last successful run, and page the API only when an export is missing. When paging, read the observables updated since the last successful run with an overlap of one hour. Use the updated time rather than the created time so observables with new opinions are included. Page through the whole window. For each observable, read the verdict counts, the latest opinion time, and the opinions with source, verdict, confidence, and publish date. Keep an observable when it meets the policy I set, by default at least one high-confidence malicious opinion, or malicious opinions from two sources, published in the last 30 days. Treat an opinion with no confidence as low. Let me restrict the sources, the observable types, and the minimum confidence. Always exclude observables that match the published address ranges of AWS, Google Cloud, Azure, and Cloudflare, domains above a Tranco rank I set, and any entry on an allowlist I maintain. Report each exclusion with its reason. Write the kept observables into one named list in the SIEM I set: a Splunk lookup table, a Microsoft Sentinel watchlist, an Elastic Security value list, a Google SecOps reference list, or a Datadog reference table. Each entry carries the observable type and value, the sources that said malicious, the highest confidence, the latest opinion date, the first time this agent added it, and an expiry I set, 30 days by default. Refresh the expiry when Mallory updates the observable and it still meets the policy. Remove entries past their expiry, and entries whose observable has a benign opinion and no malicious opinion in the last 30 days. Never write to a firewall, proxy, DNS, endpoint, or any prevention or blocking control, and never change a detection rule. Write only to the one named list, and stop and report when the list is missing or the write fails for more than a quarter of the entries. Start in a report-only mode that prints every change it would make before it writes anything.
## Requirements
It needs a Mallory API key for a tenant member, not an owner, to read observables, opinions, and the IOC exports. It needs write access to the one named list in the SIEM and read access to confirm its contents, and nothing more. It never changes detection rules or any blocking control, and changes nothing in Mallory. Related templates
-
CVE Enrichment
Builds one record per CVE from KEV, EPSS, NVD, and OSV, and, when asked, reads the upstream fix to state the exact conditions under which the vulnerability applies.
Featured Threat Intelligence / Vulnerability Management 6 tools -
Datadog Detection Posture Report
Delivers a weekly report on Datadog Cloud SIEM log ingestion gaps, detection rules that are disabled, erroring, or blind, and anything in the organization that needs an admin, from Security Filter exclusions to silent Agents.
Reporting and Compliance / Security Operations 1 tools -
Datadog Detection Tuning
Finds the Datadog Cloud SIEM detection rules that produce the most noise, reads each one against the signals it raised, and proposes a specific tuning change with the evidence and what it would have missed.
Security Operations 1 tools -
Elastic Security Detection Posture Report
Delivers a weekly report on Elastic Security data stream gaps, detection rules that are failing, warning, or blind, and anything in the deployment that needs an admin, from offline Elastic Agents to lifecycle errors.
Reporting and Compliance / Security Operations 1 tools