Overview of how Cortex XSOAR indicators are detected and ingested.
The following table shows methods by which indicators are detected and ingested in Cortex XSOAR.
Method | Description | Classification and Mapping |
---|---|---|
Integration | Feed integrations: Fetch indicators from a feed, for example TAXII, Office 365, and Unit 42 ATOMS Feed. | Indicator classification and mapping is done in the Feed Integration code and not in the Cortex XSOAR → → → → tab. |
Indicators are extracted from selected incidents that flow into Cortex XSOAR, for example from a SIEM integration. | Only the value of an indicator is extracted, so no classification or mapping is needed. | |
Manual |
| Data is inserted manually via the UI so no classification or mapping is needed. If importing a STIX file, mapping is done via the STIX parser code. |