Using XTI with Threat Intel Agent
Use the Threat Intel Agent to list, enrich, and update XTI indicators.
Agentic Assistant Threat Intel (TI) Agent works with Extended Threat Intelligence (XTI) and Threat Intel Management (TIM). The TI Agent reads from and writes to the XTI dataset. Only the actions listed below are supported.
TI Agent actions supported by XTI
The TI Agent can perform various read and write actions. The TI Agent can perform the following actions for XTI:
Action
Example prompt
List indicators
Show me the most recent malicious IP indicators
List indicator relationships
Show me relationships with 183.132.45.96
Update Indicator
Update 1.1.1.10 to verdict Benign
Enrich Domain
Enrich File
Enrich IP
Enrich URL
Show me information about 192.43.254.85
Related links
For general information and best practices related to enabling and using Agentic Assistant chat, see Agentic Assistant chat.
Last updated
Was this helpful?
