Threat Intelligence Orchestration
Threat Intelligence Orchestration activities allow users to determine whether a threat has been seen before in other security incidents or on other systems using workflow orchestration.
For more information on editing Security Incident Response Orchestration workflows or creating custom workflows, see Getting started with workflows and Workflow editor Workflow editor.
- Set up Threat Intelligence Orchestration
Prior to using Threat Intelligence Orchestration, perform steps to set up various parts of the system, including populating the CMDB, configuring the MID Server, and configuring credentials. - Threat Intelligence Orchestration workflows and activities
The base system includes workflows and workflow activities you can use to automate actions on your instance.
Parent Topic:Threat Intelligence
Related topics
Understanding Threat Intelligence
MITRE-ATT&CK framework overview
Threat Intelligence administration