You can have a single file indicator for file objects in Cortex XSIAM or each file can have a hash as its own indicator.
Cortex XSIAM uses a single File indicator for file objects. As a result, files that appear with their SHA256 hash and all other hashes associated with the file, (MD5, SHA1, and SSDeep) are listed as properties of the same indicator. In addition, when ingesting an incident through an integration, all file information is presented as one object.
When investigating an incident, in the Indicators field (Investigation or Case info tabs), click a File indicator. You can see additional information for that indicator, including:
SHA256
MD5
SHA1
SSDeep
Associated File Names
The
File.Name
values associated with the indicator hash, based onFile
context objects created in Cortex XSIAM (automatically populated).Modified
The date and time the File indicator was last modified.
First Seen
The date and time the file was first seen in Cortex XSIAM.
If the file appears in a different incident with a different name and has any of the same hash values, it automatically associates with the original indicator.
Note
A new File indicator only affects new indicators ingested to the Cortex XSIAM platform. Indicators that were already in Cortex XSIAM continue to appear as their respective hash-related indicators.