Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Define an Indicator

Define an Indicator.

Before you begin

Role required: sn_sec_tisc.analyst

Procedure

  1. Navigate to Workspaces > Threat Intelligence Security Center > Threat Intel Library > Indicators.

  2. Select Indicator.

  3. Click New.

    Note: Whenever you create new object records for observables, indicators, entities or objects a source record is created and a prompt message is displayed that the new object record is created and then the user is redirected to the aggregated record.

  4. On the form, fill in the fields.

FieldDescription
IDUnique ID of the indicator.
DescriptionDescription of the indicator.
NameName of the indicator.
PatternThe detection pattern for this Indicator may be expressed as a STIX Pattern.
Pattern TypeThe pattern language used in this indicator.
Pattern VersionThe version of the pattern language that is used for the data in the pattern property which must match the type of pattern data included in the pattern property.
Valid FromThe time from which this Indicator is considered a valid indicator of the behaviors it is related or represents.
Valid UntilThe time after which this Indicator should no longer be considered a valid indicator of the behaviors it is related to or represents.
IOC ClassificationThe IOC classification of the indicators.
Indicator TypesIndicates the various categories of the indicator.
StatusIndicates the status of the indicators.
PlatformsDefines the platforms for which this indicator is applicable for.
TLPUnique value that indicates the Data sensitivity setting per TLP.
Attack PhasesRepresents attack phase in a kill chain such as LM, MITRE ATT&CK.
ConfidenceEnter the confidence for this indicator record.The confidence property identifies the confidence that the creator has in the correctness of their data. The confidence value MUST be a number in the range of 0-100.
Threat LevelIndicates the threat level of the indicator record.
Expiration TimeSpecifies the expiration time of the indicator record.
Threat SeverityIndicates the threat severity of the indicator record.
Usage CategoriesCategories that the observable falls under, such as botnet or phishing.
First SeenThe time that this indicator record was first seen performing malicious activities.
Last SeenThe time that this indicator record was last seen performing malicious activities.
SourceSpecifies the threat source from which this record is created.
RevokedIndicates that the revoked objects are no longer considered valid by the object creator.
|Field|Description|
|-----|-----------|
|Notes|Add any additional notes for an indicator.|
FieldDescription
Additional ContextAdd any additional context for this indicator.
Spec VersionThe version of the STIX specification used to represent the indicator.The value of this property must be 2.1 for STIX Objects defined according to this specification.
LangThis property identifies the language of the text content in this object.
CreatedSpecifies the time when the indicator is created in system.
UpdatedSpecifies the time when the indicator is updated in system.
ExtensionsIndicates the extensions of indicator.
Processing StatusRepresents the processing status of this indicator.
  1. Click Save.

    After you save, a prompt message is displayed indicating that A new observable record is created. Click Continue to edit the record and create new relationships.

  2. Click Continue.

    Important: After you create a new observable record, Prevent System Updates check box is displayed.

    Select this check box to prevent any updates from the system after the observable or indicator or STIX objects records are created.

    FieldDescription
    Tags
    Select TagsSelect the tags that are associated with an indicator.
    Add TagsAdd new tags.
    Taxonomies
    Select TaxonomySelect the Taxonomy that is associated with an indicator.
    Add Taxonomy ValuesAdd the Taxonomy values that are associated with an indicator.
    FieldDescription
    The source records details for an indicator are displayed, if any.

What to do next

You can now click any of the following related lists to view additional information about objects associated with the indicators.

Related ListDescription
MITRE TechniquesLists the MITRE techniques related to this indicator.
Attack PatternsLists the Attack Patterns source that describe the methods that adversaries attempt to compromise targets that are related to this indicator.
CampaignsLists the Campaigns Source that describe a set of malicious activities or attacks that occur over time against a specific set of targets that are related to this indicator.
Courses of ActionLists the courses of action related to this indicator.
Data SourcesLists the data sources related to this indicator.
Data ComponentsLists the data components related to this indicator.
IdentitiesLists the identities that are related to this indicator.
IndicatorsLists the indicators that are related to this indicator.Note: This section also contains the potential relationships between two indicators. For more information, see Confirm indicator-indicator potential relationshipsand see Define indicator-indicator relationships for the confirmed relationships between the two observables.
InfrastructureLists the Infrastructure Source that describe any systems, software services, and any associated physical or virtual resources intended to support some purpose of an attack that are related to this indicator.
Intrusion SetsLists a set of adversarial behaviors and resources with common properties that are related to this indicator.
LocationsLists the geographical locations associated with the object.
MalwareLists malware source records that are related to this indicator.
Marking DefinitionsLists the marking definitions associated with this object.
Malware AnalysisLists the metadata and results of a particular static or dynamic analysis performed on a malware instance associated to this indicator.
ObservablesLists the related observable records that are related to this indicator.
Observed DataLists the observed data that are cyber security related entities such as files, systems, and networks and associated with this indicator.
SightingsLists sightings source records associated with this object.
Threat ActorsLists changes associated with the observable.
Threat EventsLists the event or situation that has the potential for causing undesirable consequences or impact that are associated with the indicator.
Threat GroupingsLists the threat groupings as objects that have a shared context.
Threat NotesLists the threat notes that convey information to provide further context or analysis that are associated with the indicator.
Threat OpinionsLists the threat opinions as an assessment of the accuracy of the information that are associated with the indicator.
Threat ReportsLists the threat reports associated with this indicator.
ToolsLists the tool associated with this object.
VulnerabilitiesIf the observable is an IP address, this list shows any resources \(configuration items\) that have a matching IP address.
Related CasesLists the related cases that are associated with this indicator.
Related Case TasksLists the related case tasks that are associated with this indicator.
Related CanvasesLists the related canvases that are associated with this indicator.
Indicators ReferencesList of external references that describes this indicator.

Note:

  1. You can link and unlink the related records associated with this object. For more information, see Link Threat Intel Related Records.
  2. Also, from the Related Records section, you can confirm the relationships between two Observables using the Potential Relationships section available on the Indicators form view. For more information on see, Confirm Potential Relationships from Related Records.
  3. You can add indicators to cases. For more information, see Add to Case.

Parent Topic:Indicators