Threat intel investigation through XQL
Use Cortex XSIAM XQL to query XTI indicators, threat objects, and relationships for threat intelligence investigations.
XTI is integrated into the Cortex Query Language (XQL) system, empowering you to create investigations and hunt queries using the full depth of the XTI intelligence library.
You can query threat intel indicators and threat objects through the XQL Search Portal by navigating to Investigation & Response → Search → Query Builder.
The following threat intel XQL datasets are available:
Dataset name
Description
threat_intel_indicators
Contains all active threat intel indicators with their attributes.
threat_intel_threat_actors
Contains all threat intel actors with their attributes.
threat_intel_malware
Contains all threat intel malware families with their attributes.
threat_intel_relationships
Describes associations between threat objects (threat actors, malware families) and indicators.
issue_to_indicator
Correlates threat intel data with issues data.
Select the Schema tab to see all fields available for each dataset.
Related links
For general information about XQL, see Cortex XSIAM XQL.
Using XTI datasets in correlation rules
Using XTI datasets in correlation rules is not supported. Contact Palo Alto Networks if you have any questions.
Last updated
Was this helpful?
