Views:

Search TrendAI™ threat intelligence by indicator of compromise (IoC) to verify whether an object is known to be malicious, covered by a detection, and associated with known threats.

The Indicators tab in Threat Intelligence Hub supports the following object types:
  • File hash: SHA-1, SHA-256, or MD5
  • IP address
  • Domain
  • URL
Access the Indicators tab from Threat IntelligenceThreat Intelligence Hub.
Action
Description
Run a single query.
Select Single query, enter a file hash, IP address, domain, or URL in the search field, then submit the query. The result is added to the Query history table.
Run a bulk query.
Select Bulk query to validate multiple objects at once.
  1. Click Download sample file to get the CSV template.
  2. Fill in the objects following the sample format, then upload the file. You can query up to 1,000 IoCs per CSV file.
  3. Bulk queries are processed asynchronously. After processing completes, the queried objects appear in Query history, where you can review results and apply response actions.
Review query results.
The Query history table lists every previously queried object. Each entry includes the following information:
  • Object: The queried indicator value, for example a file hash, IP address, domain, or URL. Click the object to view detailed information.
  • Object type: The type of the queried object, for example File MD5, File SHA-1, File SHA-256, IP address, Domain, or URL
  • Detection name: The TrendAI™ detection name assigned to the object, if TrendAI™ has determined the object to be malicious and covers it with a detection. Displays a dash if no detection exists.
  • Sandbox analysis: The Sandbox Analysis result for the object, if the object has been analyzed. Displays a dash if the object has not been submitted.
  • Associated threats: The number of known threats, emerging threats or threat actors, associated with the object. Click the number to view the associated threats.
  • Third-party insights: Detection results from third-party intelligence sources, shown as a ratio, for example 33/74 for the number of sources flagging the object as malicious out of the total sources queried
  • Last query time: The date and time the object was most recently queried, in YYYY-MM-DD HH:MM:SS format. Results are sorted by this column by default.
Filter the Query history table.
Select options to display objects with specific criteria:
  • Object type: Filter by the type of queried object. Default: All.
  • Sandbox analysis: Filter by sandbox analysis result. Default: All.
Export the Query history table.
Click Export to download the table contents as a CSV file.
Apply response actions to one or more objects.
Select the check box next to one or more objects to display the action toolbar:
  • Create report and sweep: Creates a custom intelligence report from the selected objects and starts a sweep of your environment for matches.
    1. Type a Report name.
    2. Optionally, select Extract domain, file SHA-1, file SHA-256, IP address, and URL objects then add them to the Suspicious Object List to also add the extracted objects to the Suspicious Object List. Selecting this option displays additional settings:
      • Risk level: Select the risk level to assign to the extracted objects.
      • Select the action to apply for each detected object type: Domain, File SHA-1, File SHA-256, IP address, and URL.
      • Expiration: Select whether the extracted objects automatically expire from the Suspicious Object List after a specified number of days, or never expire.
    3. Click Submit.
    A confirmation message displays when the report is created and the sweep starts. If report creation or sweeping fails, refresh the page and try again.
  • Query in XDR Data Explorer: Opens XDR Data Explorer to search your environment's activity data for the selected objects.
  • Send to Sandbox: Submits the selected URL objects to Sandbox Analysis for analysis in a secure virtual environment. Only URL objects support this action.
  • Add to block list: Adds the selected objects to the Suspicious Object List for detection and response by connected products.
  • Delete: Removes the selected entries from Query history.