Overview of how Cortex XSIAM indicators are detected and ingested.
The following table shows methods by which indicators are detected and ingested in Cortex XSIAM.
Method | Description | Classification and Mapping |
---|---|---|
Integration |
| Indicator classification and mapping is done in the Feed Integration code and not in the Cortex XSIAM → → → → tab. For example, see the Unit 42 Intel Objects Feed integration. |
Indicators are extracted from selected incidents that flow into Cortex XSIAM, for example from an integration, such as EWS. | Only the value of an indicator is extracted, so no classification or mapping is needed. | |
Manual |
| Data is inserted manually via the UI so no classification or mapping is needed. If importing a STIX file, mapping is done via the STIX parser code. |