Extended Threat Intelligence
Research threats, investigate indicators, and apply intelligence across Cortex Cloud Runtime Security workflows.
Extended Threat Intelligence overview
Extended Threat Intelligence (XTI) offers operationalized Threat Intelligence (TI) seamlessly integrated across the Cortex platform.

XTI offers the following core capabilities:
Threat Intel Library: Powered by Unit 42 threat intel data, the Threat Intel Library provides a unified catalog of curated threat objects (threat actors, malware families, vulnerabilities, and reports), helping you understand the broader threat landscape.
XTI Indicators: XTI indicators include first-party indicators, as well as observables extracted from detections and customer-managed indicators.
TI context in case and issue investigations: Cases and issues are enriched with the XTI threat intelligence, providing SOC analysts with threat intel context during case and issue investigations.
AI-driven Behavioral Threat Analysis (BTA): XTI correlates observed behaviors and evidence from security cases and issues with known threat actor Tactics, Techniques, and Procedures (TTPs).
TI investigations through XQL: Build investigations and hunt queries, and correlate threat intel data with issues data through Cortex Query Language (XQL) using the full depth of XTI intelligence library.
Interactive TI dashboard: Leverage the built-in XQL dashboard summarizing threat intel relevant to your organization, and clone and modify it as needed.
Indicator/IOC detections: Continuously monitor your environment for known threat indicators with automated issue generation and dynamic targeting.
Threat-aware automation and response: Utilize built-in commands in playbooks to automate TI triage, enrichment, and response.
Accessible TI with AgentiX: Natural language assistance for TI search and explanations powered by AgentiX.
What license do I need to use XTI?
To use XTI, you must have the Cortex XDR license with the Extended Threat Intelligence (XTI) add-on.
If you have the correct license, you can access Cortex XTI by navigating to Threat Management → Threat Intelligence.
Permissions required for XTI
XTI requires View or View/Edit RBAC permissions for Threat Intelligence in the Threat Management component tab.
Using indicator rules requires View or View/Edit RBAC permissions for both Threat Intelligence and Rules in the Threat Management component tab.
Using XTI with platform features such as cases and issues or dashboards requires additional feature-specific permissions.
Last updated
Was this helpful?
