Overview of how Cortex XSOAR indicators are detected and ingested.
The following table shows methods by which indicators are detected and ingested in Cortex XSOAR.
Classification and Mapping
Feed integrations: Fetch indicators from a feed, for example TAXII, Office 365, and Unit 42 ATOMS Feed.
Indicator classification and mapping is done in the Feed Integration code and not in the Cortex XSOAR → → → → tab.
Indicators are extracted from selected incidents that flow into Cortex XSOAR, for example from a SIEM integration.
Only the value of an indicator is extracted, so no classification or mapping is needed.
Data is inserted manually via the UI so no classification or mapping is needed.
If importing a STIX file, mapping is done via the STIX parser code.