Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Security Operations Integration- Sightings Search capability

The Sightings Search capability accepts a set of observables, finds any integrations that support a Sightings Search, then executes these searches.

The Sightings Search capability has a workflow, Security Operations Integration - Sightings Search Flow, that executes the sightings search. This workflow accepts a list of observables, finds any implementing capabilities, creates the queries based on Sightings Search Configurations, and executes the searches based on the configured workflow. Once the search is complete, a note is added to the incident Work notes including whether any sightings were found and if so, how many.

To view Sightings Search Configurations, navigate to Security Operations > Integrations > Sightings Search Configurations.

Note: If no implementations are available, capability actions are not displayed in product menus.

Parent Topic:Integration capabilities

Related topics

Security Operations Integration- Block Request capability

Security Operations Integration- Email Search and Delete capability

Security Operations Integration- Enrich CI capability

Security Operations Integration- Enrich Observable capability

Security Operations Integration- Get Network Statistics capability

Security Operations Integration- Get Running Processes capability

Security Operations Integration- Isolate Host capability

Security Operations Integration- Publish to Watchlist capability

Security Operations Integration - Threat Lookup capability

Change the order of flow execution