Publish observables to a third-party watchlist
You can publish one or more observables or associated indicators to a third-party watchlist. Currently, the only implementation that supports this functionality is CrowdStrike Falcon Host.
Before you begin
Role required: sn_si.analyst
About this task
Note: If no implementations are available, capability actions are not displayed in product menus.
Procedure
Navigate to a security incident.
Select Observables from the Related List tab.
Select Publish to Watchlist in the Actions on selected rows... drop-down menu.
The Publish to Watchlist dialog box appears.
Enter or choose the implementation.
Note: A workflow is triggered by the Security Operations Integration- Publish to Watchlist capability when you select the CrowdStrike Falcon Host implementation.
Select Submit.