Overview of how Cortex XSOAR indicators are detected and ingested.
The following table shows methods by which indicators are detected and ingested in Cortex XSOAR.
Method | Description | Classification and Mapping |
---|---|---|
Integration |
| Indicator classification and mapping is done in the Feed Integration code and not in the Cortex XSOAR Settings > OBJECTS SETUP > Indicators > Classification & Mapping tab. For example, see the FeedUnit42v2 integration. |
Indicators are extracted from selected incidents that flow into Cortex XSOAR, for example from a SIEM integration. | Only the value of an indicator is extracted, so no classification or mapping is needed. | |
Manual |
| Data is inserted manually via the UI so no classification or mapping is needed. If importing a STIX file, mapping is done via the STIX parser code. |