> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/extended-threat-intelligence/threat-intel-context-in-cases-and-issues.md).

# Threat intel context in cases and issues

Cortex identifies indicators from your existing detections generated by other modules. The system extracts these indicators at the issue level and aggregates them at the case level.

When an indicator is associated with an issue, you can view the threat intelligence context in the case and in the issues grouped under it, as follows.

## Analyzing threat intel in a case

You can access threat intel context for a case as follows:

### Case overview

In the **Overview**, under **Artifacts**, you can see indicators extracted from the case.

Expand each indicator that is listed here and hover over it to access more information about it, including **XTI Verdict**:

<figure><img src="/files/HZBNY3jI8ROYXJTOfntp" alt="This screenshot from Cortex UI shows the indicators listed under Artifacts in Overview view of a case." height="349" width="299"><figcaption></figcaption></figure>

### Threat Intel tab

In the **Detailed** view of a case, access threat intel context through the **Threat Intel** tab. When indicators are identified in one or more issues grouped under the case, the tab includes overview widgets and a list of the aggregated indicators.

The following screenshot shows the **Threat Intel** tab and its content:

<figure><img src="/files/06wk8hiKKXCENLuOdsrM" alt="This screenshot from Cortex UI shows the threat intel tab in the Details view of a case." height="263" width="624"><figcaption></figcaption></figure>

The following widgets help you understand the indicators associated with the case:

* **Malicious indicators by type**: Shows the breakdown of malicious indicators by type. Select the indicators in the widget to filter the indicators shown in the table.
* **Verdict breakdown**: Shows the breakdown of all indicators by verdict. Select the verdicts in the widget to filter the indicators shown in the table.
* **Associated Threat Objects**: Links threat actors and malware families associated with the indicators. Select to filter the results below.

The Associated Indicators list provides the following information:

* **Type**: Indicator type (Domain, File Hash, IP or URL)
* **Value**: A specific domain name, file hash, IP address or URL
* **Threat actors**: Threat actors associated with the indicator.
* **Malware families**: Malware families associated with the indicator.
* **Verdict**: Indicator verdict.

Select a specific row to open the indicator’s XTI entry in a side panel, where you can review the associated threat actors, malware families, as well as XTI Verdict.

## Analyzing threat intel in an issue

When investigating an issue using the **Investigate** option, there is a section called **Indicators** in the issue **Overview** that lists indicators extracted from the issue:

<figure><img src="/files/OblFMNHddF6jOCQrCWLq" alt="This screenshot from Cortex UI shows indicators associated with a specific issue, visible in the Overview of an issue." height="188" width="624"><figcaption></figcaption></figure>

For each indicator, you can see the associated threat actors, malware families associated with that indicator, as well as XTI Verdict.

You can select each indicator to view the **XTI Indicator** side pane.

**Related links**

For general information about cases and issues, see [Investigation and response](/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response.md).

## Behavioral Threat Analysis (BTA)

XTI performs Behavioral Threat Analysis (BTA) on eligible cases and displays any significant findings. BTA correlates observed behaviors and evidence from security cases and issues with known threat actor Tactics, Techniques, and Procedures (TTPs).

BTA uses an agentic inference pipeline to integrate threat intelligence with the rich telemetry of your environments, categorizing each case and providing potential attribution to help analysts quickly understand the nature and origin of a threat.

BTA performs the following actions:

* **Categorizes threats**: Automatically analyzes a case and predicts if the activity is an APT Attack, Cyber Crime, Attack Simulation Tool, or Non-attributable.
* **Provides actor attribution**: For APT Attacks or Cyber Crime, supplies up to three likely actor hypotheses (for example, identifying a specific threat group) using relative likelihood labels like "Most Likely," "Possible," and "Less Likely."
* **Delivers country attribution**: For APT attacks, provides a predicted country of origin to help trace the attack's source.
* **Supplies evidence and rationale**: Provides the model's reasoning, evidence details, and direct links to supporting Unit 42 or OSINT publications.
* **Reconciles context**: Evaluates the "totality of case evidence"—including all extracted indicators, their relationships, and behavioral patterns—to provide a highly contextualized attribution story.

### Supported regions

BTA is only available on Cortex tenants located in the following regions:

Americas

* United States (US)
* Canada (CA)

EMEA

* Italy (IT)
* Netherlands
* Spain (ES)
* United Kingdom (UK)

JPAC

* India (IN)
* Singapore (SG)

### BTA eligibility

BTA is automatically generated for cases with high or critical severity. You can also run BTA manually on cases with lower severity.

### BTA categories

Here is the breakdown of how the BTA logic processes a case to issue a threat intelligence summary and categorize an attack, attributing it into one of four primary categories depending on the nature of the activity.

| **BTA category**  | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| ----------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| APT Activity      | <p>If the activity is classified as an <strong>Advanced Persistent Threat (APT) Activity</strong>, the system evaluates whether specific Threat Actor (TA) attribution is possible:</p><ul><li><strong>No Threat Actor Attribution</strong>: If the specific threat actor cannot be identified, the system defaults to showing general country-level attribution.</li><li><strong>With Threat Actor Attribution</strong>: If a specific threat actor is identified, the system provides deeper context alongside the nation-state origin. Up to three suspected actors are displayed with one identified as the most likely to be responsible for the activity.</li></ul> |
| Cybercrime        | <p>If the activity is classified as financially motivated <strong>Cybercrime</strong>, the system evaluates attribution at the criminal level:</p><ul><li><strong>No Threat Actor Attribution</strong>: If the specific threat group or individual cannot be pinned down, the logic stops at identifying the general category.</li><li><strong>With Cybercriminal Attribution</strong>: If the specific cybercriminal group or campaign can be identified, it provides targeted threat actor attribution. Up to three suspected actors are displayed with one identified as the most likely to be responsible for the activity.</li></ul>                                 |
| Attack Simulation | If the system detects that the activity is an authorized security test or training exercise, it bypasses all actor or country attribution entirely and simply generates an overview of the event.                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| Non Attributable  | If the activity does not fit into the threat or simulation categories, or lacks any defining behavioral footprints, it categorizes it as **Non Attributable** and provides a standard high-level overview.                                                                                                                                                                                                                                                                                                                                                                                                                                                                |

### BTA summary in Threat intel

XTI performs Behavioral Threat Analysis (BTA) on eligible cases and displays any significant findings. If BTA findings have been generated and displayed for a case, you can find them listed under **AI Behavioral Threat Analysis** in the **Threat Intel** tab.

When BTA attribution is displayed, a confidence level in the results is included (“Very High Confidence” or “High Confidence”). If confidence level is lower, BTA results are not displayed.

The following screenshots illustrate examples of the **Threat Intel** tab with BTA output displayed in it.

#### APT Activity

In this example, the system determined the activity to be an APT activity:

<figure><img src="/files/NRCel5yg86FOq7XLkNPf" alt="This screenshot from Cortex UI shows a case that BTA determined to be an APT activity." height="360" width="624"><figcaption></figcaption></figure>

You can see the title and the summary of the findings, as well as suspected actor(s) (if attributed) and suspected origin (if attributed). To the right, you can find the widget visualizing threat associations.

Select **Suspected Actor** to review the list of threat actors. Select a specific actor to view it in XTI Threat Intel Library.

Select the ![](/files/W1RWQvqGZyGsb7OppErU) (down arrow) to expand the BTA summary.

If a threat actor has been attributed, you can access **Report Details** for each of the attributed threat actors:

<figure><img src="/files/QGK9auhxao0BVvUcmavI" alt="This screenshot from Cortex UI shows a case with citations and a list of publications generated by BTA for a specific case." height="304" width="624"><figcaption></figcaption></figure>

Select a threat actor name to view **Actor Attribution Evidence** and **Source Publications** used for the attribution. Within the **Actor Attribution Evidence**, you can access clickable citations pointing you to specific reports that were used to attribute the actor. Under **Source Publications**, you can select a publication to access more information about it in XTI Threat Intel Library.

#### Cybercrime

In this example, the system determined the activity to be a cybercrime:

<figure><img src="/files/iL7BHRr30shay9CeBgU7" alt="This screenshot from Cortex UI shows a case that BTA determined to be a cybercrime." height="409" width="624"><figcaption></figcaption></figure>

You can see the title and the summary of the findings, as well as suspected actor(s) (if attributed). To the right, you can find the widget visualizing threat associations.

Select **Suspected Actor** to review the list of threat actors. Select a specific actor to view it in XTI Threat Intel Library.

Select the ![](/files/W1RWQvqGZyGsb7OppErU) (down arrow) to expand the BTA summary.

If a threat actor has been attributed, you can access **Report Details** for each of the attributed threat actors:

<figure><img src="/files/QGK9auhxao0BVvUcmavI" alt="This screenshot from Cortex UI shows a case with citations and a list of publications generated by BTA for a specific case." height="304" width="624"><figcaption></figcaption></figure>

Select a threat actor name to view **Actor Attribution Evidence** and **Source Publications** used for the attribution. Within the **Actor Attribution Evidence**, you can access clickable citations pointing you to specific reports that were used to attribute the actor. Under **Source Publications**, you can select a publication to access more information about it in XTI Threat Intel Library.

#### Attack simulation

In this example, the system determined the activity to be an attack simulation:

<figure><img src="/files/eggaaDDkQ5VyMPz71R2P" alt="This screenshot from Cortex UI shows a case that BTA determined to be an attack simulation." height="385" width="624"><figcaption></figcaption></figure>

You can see the title and the summary of the findings. To the right, you can find the widget visualizing associated indicators.

Select the ![](/files/W1RWQvqGZyGsb7OppErU) (down arrow) to expand the BTA summary.

In **Report Details**, you can see Evidence Summary about the observed activity.

#### Non-attributable

In this example, the system determined the activity to be non-attributable:

<figure><img src="/files/YYIDIEKbqJ1HvEQHRCOP" alt="This screenshot from Cortex UI shows a case that BTA determined to be an non-attributable." height="188" width="624"><figcaption></figcaption></figure>

You can see the title and the summary of the findings. To the right, you can find the widget visualizing associated indicators.

Select the ![](/files/W1RWQvqGZyGsb7OppErU) (down arrow) to expand the BTA summary.

In **Report Details**, you can see Evidence Summary about the observed activity..

Under **AI Analysis based on**, you can see the sources behind the AI analysis. You can hover and/or select the text to get more information and access related reports.

### Run Behavioral Threat Analysis (BTA)

If BTA wasn’t displayed on a case automatically, you can trigger it manually.

BTA is automatically generated only for cases where severity is high or critical. If the BTA did not run automatically on a case (because case severity is lower, or the automatic pipeline is out of quota, or where it did not run for any other reason), you can run BTA manually.

1. Go to the case where you would like to run BTA.
2. Select the **Threat Intel** tab.
3. Select **Run Behavioral Threat Analysis**.

Results typically appear within a few minutes. Results only display when confidence is high. Otherwise, the message "Behavioral Threat Analysis last ran on {date} and produced no notable findings" appears.

<br>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/extended-threat-intelligence/threat-intel-context-in-cases-and-issues.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
