Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Define object-indicator relationships

Define relationships between the indicator object and other SDOs.

Before you begin

Role required: sn_ti.admin

Procedure

  1. Navigate to All > Threat Intelligence > IoC Repository > Object-Indicator-Relationships.

  2. Click New.

  3. Complete the fields in the form as appropriate.

    FieldDescription
    ObjectSelect and define the object.
    TypeSpecifies the object type based on the object you selected.
    IndicatorSelect the indicators of compromise.
    Relationship DirectionDefine the relationship direction whether it is direct or inverse.
    Relationship TypeA description that provides more details and context about the relationship type.
    SourceSpecifies the threat source from which this record is created.
    Source IDUniquely identifies the source object.
  4. Click Submit.

Parent Topic:Relationships