Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

View an IoC

IoCs, sometimes referred to as indicators, are most typically retrieved from a threat data source as STIX data. If needed, you can also create IoCs.

Before you begin

Role required: sn_ti.write

Procedure

  1. After the scheduled job has retrieved IoC data from the defined data source, navigate to Threat Intelligence > IoC Repository > Indicators.

    The retrieved IoCs are listed.

  2. Click the IoC you want to view.

  3. The following information displays.

FieldDescription
Select classification tagIf you set up and activated security tags to add metadata to the record, you can select one or more tags to specify the degree of sensitivity of the IoC. If you did not set up or activate security tags, this drop-down list is not displayed.
TitleA descriptive name for this indicator.
First SeenThe first date this indicator was observed in the system.
Last SeenThe most recent date this indicator was observed in the system.
Encountered countThe number to times the indicator has been encountered.
Sourced countThe number to times the indicator was imported from defined threat sources.
NotesAny additional notes about the indicator. This field can also contain JSON key/value pairs.
  1. You can click any of the following related lists to view additional information.
Related Links and Related ListsDescription
Show RelationshipsOpens the STIX Visualizer where you can view the relationship of the STIX object.Show Relationships appears only when the object has an associated object.
Related ObservablesLists observables that are linked to the current indicator.
Related Attack mode/methodLists related attack modes/methods that have been identified as related to this indicator.
Associated TypeLists other indicator types that are associated with this IoC.
Indicator SourcesLists the sources of this indicator, along with the confidence level of the source.
Associated TasksLists all tasks, changes, and incidents associated with the IoC.
Indicator MetadataIf the Notes field contains valid JSON key/value pairs, they are parsed and displayed. If no JSON key/value pairs are present, or if the JSON is invalid, this related list is not displayed.
Security Annotations 
Indicator External References 
Associated Kill Chain PhasesLists kill chain phases associated with this object.
Attack PatternsLists the attack patterns that help categorize attacks that are associated with this object.
CampaignsLists campaigns associated with this object.
Intrusion SetLists a set of adversarial behaviors and resources with common properties associated with this object.
MalwareLists malicious code associated with this object.
Threat ActorsLists individuals, groups, or organizations who act with malicious intent associated with this object.

Parent Topic:Indicators of compromise

Related topics

Add a related observable to an IoC

Add a related attack mode/method to an IoC

Identify associated indicator types

Identify indicator sources

Add associated tasks to an IoC