Deleting threat intelligence library records
Delete threat intelligence library records such as observables, indicators, and objects.
Before you begin
Role required: sn_sec_tisc.analyst
The following example procedure explains how to delete an observable record. You can use the same procedure to delete indicators or objects as well.
Procedure
Navigate to Workspaces > Threat Intelligence Security Center > Threat Intel Library > Observables > All Observables.
Open any observable record.
Select Delete to delete the aggregated record.
When you select this action, then it will remove all the related records, except the original source data, and trigger reaggregation.
A confirmation message will appear to verify that you want to delete the aggregated record. If you also want to delete the source records and prevent re aggregation, select the Delete Source Records check box. This action will remove all the associated source records.
Delete library records
Select Delete.
The record will be deleted from threat intelligence library.
What to do next
Refer to the section Define an Observable to create a record.
Parent Topic:Threat Intel Library
Related topics
TISC Library Objects form view
Access Vulnerability Downstream actions