Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Define object-observable relationships

Define relationships between SDOs and the observable object (SCO).

Before you begin

Role required: sn_ti.admin

Procedure

  1. Navigate to All > Threat Intelligence > IoC Repository > Object-Observable-Relationships.

  2. Click New.

  3. Complete the fields in the form as appropriate.

    FieldDescription
    ObjectSelect and define the source object.
    TypeEnter a descriptive name to identify the object type.
    ObservableSelect and define the observable.
    Relationship TypeA description that provides more details and context about the relationship type.
    SourceSpecifies the threat source from which this record is created.
    Source IDUniquely identifies the source object.
  4. Click Submit.

Parent Topic:Relationships