Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Observables

Observables represent stateful properties (such as the MD5 hash of a file or the value of a registry key) or measurable events (such as the creation of a registry key or the deletion of a file) that are pertinent to the operation of computers and networks.

Following are the type of observables available in the application:

  • Artifact
  • AS Number
  • Directory
  • Domain Name
  • Email Address
  • Email Message
  • Email Subject
  • File
  • IPv4 Address
  • IPv4 CIDR
  • IPv6 Address
  • IPv6 CIDR
  • MAC Address
  • MD5 Hash
  • Mutex Name
  • Network
  • Other Observable
  • Process
  • SHA1 Hash
  • SHA256 Hash
  • SHA512 Hash
  • Software
  • URL
  • User Account
  • Windows Registry Key
  • X.509 Certificate

  • Define an Observable
    Observables can be retrieved from scheduled feed ingestion or from the import assistant. However, you can create observables, as needed.

  • Observables source records
    The source records contribute to an aggregated record as displayed in the form view. These source records are auto created from feeds or manually created by the user.
  • Link Threat Intel Related Records
    Link the records that are related to the corresponding threat intelligence objects.
  • Fetch Observables Data
    Fetch the observables related records data.
  • View details in Visualizer
    Using the Visualizer, you can view the relationships between objects, observables and indicators which provides context for you to further investigate. The Visualizer uses colors and icons to illustrate various information about the objects.
  • Working with Internal Intelligence Records
    Use this feature to work with the internal intelligence data that is collected from Configuration Database Management System (CMDB) into Threat Intelligence Security Center.
  • Run Enrichment Actions from Observable
    Use this section to understand how enrichments actions are performed on observables and other objects.
  • Add to Case
    Add observables, indicators, or other objects to the case.
  • Run Enrichment operations in TISC
    The following table below describes the interactions involved in running different enrichment operations from TISC.
  • View Enrichment Results
    View observables, indicators, and various objects enrichment results.

Parent Topic:TISC Library Repository

Related topics

Indicators

Threat Entities

Other Objects

Vulnerability Artifacts

View RSS Feeds

Working with Reports in TISC

MITRE-ATT&CK Repository

Relationships Objects

Potential Relationships

Vulnerability relationship mapping