Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Security Operations Integration - Threat Lookup capability

The Threat Lookups capability performs threat intelligence lookups to determine whether one or more observables are associated with known security threats.

The Threat Lookups capability has a workflow, Security Operations Integration - Threat Lookup Flow. When the capability workflow runs, it executes additional workflows for the activated implementations. You can specify an implementation to use to perform a lookup on the selected observables, or you can perform the lookup using all implementations.

Note: If no implementations are available, capability actions are not displayed in product menus.

  • Security Operations Integration - Threat Lookup Flow
    The Security Operations Integration - Threat Lookup capability flow accesses available threat lookup implementations and executes the implementation flows associated with each to perform threat lookups of selected observables.

Parent Topic:Integration capabilities

Related topics

Security Operations Integration- Block Request capability

Security Operations Integration- Email Search and Delete capability

Security Operations Integration- Enrich CI capability

Security Operations Integration- Enrich Observable capability

Security Operations Integration- Get Network Statistics capability

Security Operations Integration- Get Running Processes capability

Security Operations Integration- Isolate Host capability

Security Operations Integration- Publish to Watchlist capability

Security Operations Integration- Sightings Search capability

Change the order of flow execution