F5 BIG-IP STIX/TAXII Threat Intelligence iApp

This solution provides an enterprise-grade F5 BIG-IP iApp template and enforcement engine that automates the ingestion of Threat Intelligence Indicators of Compromise (IOCs) from:

  • STIX 2.1 / TAXII 2.1 servers
  • Remote HTTP/HTTPS feeds
  • Local files

The solution provides real-time L4/L7 threat blocking on selected Virtual Servers permitting to define which Application to protect and the prefered ingestion method to use.

Key Features:

  • 100% Self-Contained Deployment: The iApp template embeds the complete Python ingestion engine as a Base64 payload. Deploying the template automatically provisions /shared/scripts/stix_taxii_importer.py with executable permissions on the BIG-IP without requiring manual file transfers over SSH/SCP.
  • Virtual Server Protection Modes: Specify existing target Virtual Server(s) or deploy in standalone mode (Data Groups & background polling only).
  • Automated Multi-Source Threat Feed Ingestion:
    • OASIS TAXII 2.1: Connects to discovery roots and collection endpoints with dynamic API root traversal and strict RFC headers.
    • MISP Threat Feeds: Direct ingestion of Threat feeds in JSON format, with automated multi-bulletin aggregation via manifest.json.
    • Local PC File Upload: Direct support for files uploaded through TMOS GUI (System > File Management > Data Group File List > Import).
    • Plain Text / CSV Feeds: Supports custom blocklists in the plain text / CSV format.
    • Export of threat feeds using secure cli connection or via Data Group Export.

Deployment Options

Step 1: Import the iApp Template

  1. In the BIG-IP GUI, navigate to iApps > Templates > Templates.
  2. Click Import….
  3. Select stix_taxii_blocker.iapp.tmpl and click Upload.

Step 2: Instantiate the iApp Service

  1. In the BIG-IP GUI, navigate to iApps > Application Services > Applications.
  2. Click Create….
  3. Select stix_taxii_blocker from the Template dropdown.
  4. Configure the parameters.
  5. Click Finished.
Section Parameter Description
Virtual Server Protection Mode Choose Protect an Existing Virtual Server or Standalone
Target Virtual Server Select the Virtual Server to protect (e.g. /Common/vs_https)
Inspect XFF Enable to inspect X-Forwarded-For headers behind CDNs/proxies
Threat Feed Source Choose TAXII 2.1 Server, Remote Threat Feed URL, or Uploaded File / BIG-IP Local File
TAXII URL Base URL of TAXII 2.1 discovery or collection endpoint
Collection ID Optional collection identifier (e.g. malicious-indicators)
Remote Feed URL URL of MISP JSON, ThreatFox CSV/JSON, or plain text blocklist
Uploaded / Local File Name of file imported in System > File Management or local file path
Authentication Select None, Basic Auth, Bearer Token, or API Key
Polling Schedule Choose synchronization interval (e.g., Every 5 min, 1 hour, 24 hours)
Outbound Proxy Optional egress proxy URL (e.g., http://proxy.corp:8080)
Actions Action for Malicious IPs Silently Drop, Send TCP Reset, or Log Only
Action for Malicious URLs Return Responsive 403 Block Page, Drop, Reset, or Redirect
Whitelists IP Whitelist Table Enter corporate subnets to exempt (e.g., 10.0.0.0/8, 192.168.1.0/24)
URL Whitelist Table Enter internal domains or bypass paths (e.g., internal.corp, /healthcheck)

The iApp will automatically:

  • Self-deploy the Python ingestion engine to /shared/scripts/stix_taxii_importer.py.
  • Ingest initial threat intelligence data and populate external Data Groups.
  • Generate and bind the optimized L4/L7 enforcement iRule to your Virtual Server.
  • Configure scheduled background polling via iCall / cron.

If you want to remove one of the instantiated iApp service:

  1. Reconfigure the iApp
  2. Move “Attach mode” to Standalone (this will remove the protection from the VS)
  3. Click Finished.
  4. Delete the instantiated iApp