For the complete documentation index, see llms.txt. This page is also available as Markdown.
Cortex Cloud Runtime

Using XTI with Threat Intel Agent

Use the Threat Intel Agent to list, enrich, and update XTI indicators.

Agentic Assistant Threat Intel (TI) Agent works with Extended Threat Intelligence (XTI) and Threat Intel Management (TIM). The TI Agent reads from and writes to the XTI dataset. Only the actions listed below are supported.

TI Agent actions supported by XTI

The TI Agent can perform various read and write actions. The TI Agent can perform the following actions for XTI:

Action

Example prompt

List indicators

Show me the most recent malicious IP indicators

List indicator relationships

Show me relationships with 183.132.45.96

Update Indicator

Update 1.1.1.10 to verdict Benign

Enrich Domain

Enrich File

Enrich IP

Enrich URL

Show me information about 192.43.254.85

Enrich CVE is currently not supported.

Related links

For general information and best practices related to enabling and using Agentic Assistant chat, see Agentic Assistant chat.

Last updated

Was this helpful?