For the complete documentation index, see llms.txt. This page is also available as Markdown.
Cortex XSIAM

Threat intel investigation through XQL

Use Cortex XSIAM XQL to query XTI indicators, threat objects, and relationships for threat intelligence investigations.

XTI is integrated into the Cortex Query Language (XQL) system, empowering you to create investigations and hunt queries using the full depth of the XTI intelligence library.

You can query threat intel indicators and threat objects through the XQL Search Portal by navigating to Investigation & Response → Search → Query Builder.

The following threat intel XQL datasets are available:

Dataset name

Description

threat_intel_indicators

Contains all active threat intel indicators with their attributes.

threat_intel_threat_actors

Contains all threat intel actors with their attributes.

threat_intel_malware

Contains all threat intel malware families with their attributes.

threat_intel_relationships

Describes associations between threat objects (threat actors, malware families) and indicators.

issue_to_indicator

Correlates threat intel data with issues data.

Select the Schema tab to see all fields available for each dataset.

Because XTI datasets are holistic, stateful representations rather than time-bound logs, the Time frame filter is disabled for these datasets.

Related links

For general information about XQL, see Cortex XSIAM XQL.

Using XTI datasets in correlation rules

Using XTI datasets in correlation rules is not supported. Contact Palo Alto Networks if you have any questions.

Last updated

Was this helpful?