Indicator Fields - Administrator Guide - 6.11 - Cortex XSOAR - Cortex - Security Operations

Cortex XSOAR Administrator Guide

Product
Cortex XSOAR
Version
6.11
Creation date
2022-12-12
Last date published
2024-04-15
Category
Administrator Guide
Abstract

Indicator Fields are used to add specific indicator information to indicators. Associate fields to a specific indicator type or all indicator types in Cortex XSOAR.

Indicator fields are used to add specific indicator information to indicators. When you create a custom indicator field, you can add it to the indicator layout to which you associate the field. You can then Map Custom Indicator Fields to the relevant indicator type. You can also add an Indicator Field Trigger Script that checks for field changes and enables you to automatically take action.

Note

Cortex XSOAR IOC fields are based on the STIX 2.1 specifications. For more information, see Indicator Fields Structure.