> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/threat-intel-management/indicator-management/query-indicators-with-unit-42-intel-data.md).

# Query indicators with Unit 42 Intel data

You can access Threat Intel data through the following methods:

* On the **Threat Intel** page, select an indicator to start investigating. If the indicator also exists in Unit 42 Intel, the **Unit 42 Intel** tab is available.
* When investigating an incident, select an extracted indicator. The **Quick View** shows basic information about the indicator in Cortex XSOAR and Unit 42 (if available). **Full view** shows the full Cortex XSOAR indicator summary.
* On the **Threat Intel** page, query an indicator, which may or may not be in the Cortex XSOAR intel library.

  Unit 42 Intel data is cloud-based and remotely maintained so that you can view data from Unit 42 Intel and add only the information you need to your Cortex XSOAR threat intel library. When you search for an IP address, domain, URL, or file, you can view the indicator in Cortex XSOAR and the additional information provided by Unit 42 Intel. When an indicator does not yet exist in Cortex XSOAR, but does exist in Unit 42 Intel, you can add the indicator to the Cortex XSOAR threat intel library. You can add the indicator and enrich it with your existing integrations, or add the indicator without enrichment. When the indicator already exists in Cortex XSOAR, but additional information is available from Unit 42 Intel, you can update your indicator with the most recent data from Unit 42 Intel.

  The Threat Intel library is a centralized space for all indicators, whether they are found in an incident, brought in as a feed, or added manually. You can view in-depth information on collected indicators and filter the library based on common attributes.

  <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>You can search or look up indicators. A search, which can include wildcards and complex queries, can return multiple results. Searches are only performed in Cortex XSOAR. Lookups are exact values, are performed in both Cortex XSOAR and Unit 42 Intel data, and can only return one result.</p></div>

**Indicator query considerations**

When querying directly on the **Threat Intel** page, the following considerations apply:

* Querying an IP address, domain, URL, or SHA256 file hash, without a wildcard or complex search (Boolean search, `type:file`, etc.), queries both the Cortex XSOAR threat intel library and Unit 42 Intel, with no date range limit.
* If you enter an indicator type that is not an IP address, domain, URL, or SHA256 file hash, or you enter a wildcard or complex option (Boolean search, type:file, etc.), no lookup is performed in Unit 42. In Cortex XSOAR, a search is performed. By default, the search is for the last 7 days, but you can adjust the date range.
* Wildcard searches can only be performed in the local Cortex XSOAR threat intel library, and not in Unit 42 Intel data. Example: \*xample.com
* Complex searches are only conducted in the local Cortex XSOAR threat intel library, and not in Unit 42 Intel data. Example: `type:URL` and `verdict:Malicious`.
* For files, only the SHA256 hash returns Unit 42 Intel data.
* For a query to include Unit 42 Intel results, it must be a lookup for an exact match.

You can search for indicators using any of the available search fields. This is a partial list of the available search fields.

| Field                       | Description                                                                                                          |
| --------------------------- | -------------------------------------------------------------------------------------------------------------------- |
| **`type`**                  | The type of the indicator, such as File or Email.                                                                    |
| **`verdict`**               | <p>The reputation of the indicator:</p><ul><li>Malicious</li><li>Suspicious</li><li>Benign</li><li>Unknown</li></ul> |
| **`aggregatedReliability`** | Searches for indicators based on a reliability score such as **`A - Completely reliable`**.                          |
| **`sourceBrands`**          | Indicator feed or enrichment integrations.                                                                           |
| **`sourceInstances`**       | A specific instance of an indicator feed or enrichment integration.                                                  |
| **`expirationSource`**      | The source (such as script or manual.) that last sets the indicator's expiration status.                             |
| **`tags`**                  | Tags applied to indicators.                                                                                          |
| **`comments`**              | Search for keywords within indicators’ comments.                                                                     |

You can use a wildcard query, which finds indicators containing terms that match the specified wildcard. For example, the **`*`** pattern matches any sequence of 0 or more characters, and **`?`** matches any single character. For a regex query, use the following value:

`"/.*\\?.*/"`

**Indicator queries and Unit 42**

Unit 42 Intel data is not automatically added to the Cortex XSOAR Threat Intel library. When you query for an indicator on the Threat Intel page, in some cases the indicator is not in the Threat Intel library, but exists in Unit 42 Intel. In other cases, the indicator may already be in the Cortex XSOAR Threat Intel library, but more in-depth information is available from Unit 42 Intel.

When a query is performed in both Cortex XSOAR and Unit 42 Intel, there are four possible results:

<details>

<summary>The indicator exists in Cortex XSOAR but does not exist in Unit 42 Intel</summary>

The Cortex XSOAR search result is displayed in a table. Click on the value to reach the **Summary** tab. The **Summary** tab presents information about the indicator stored in Cortex XSOAR. The **Unit 42 Intel** tab is disabled.

</details>

<details>

<summary>The indicator exists in Unit 42 Intel, but does not exist in the Cortex XSOAR threat intel library</summary>

To view the Unit 42 Intel data for this indicator, click on the indicator search term in blue.

![unit42-search-not-in-xsoar.png](/files/VsYmPLT4G5ys27HWuQnc)

From the **Unit 42 Intel** tab, you have the option to add the indicator to Cortex XSOAR or to add and enrich the indicator to Cortex XSOAR.

* **Add to XSOAR**

  The indicator is added to Cortex XSOAR. If the indicator is related to one or more Unit 42 threat intel objects already in Cortex XSOAR (ingested through the Unit 42 Feed integration), relationships are created in the database between the Unit 42 threat intel objects and the file indicator. No third-party enrichments are run on the indicator. We recommend using this option if, for security reasons, you do not want to expose the indicator to any third-party services.
* **Add to XSOAR & Enrich**

  The indicator is added to Cortex XSOAR. If the indicator is related to one or more Unit 42 threat intel objects already in Cortex XSOAR (ingested through the Unit 42 Feed integration), relationships are created in the database between the Unit 42 threat intel objects and the file indicator. Your configured third-party enrichments are run on the indicator.

When you add indicators to the Cortex XSOAR threat intel library from Unit 42 Intel, the indicators are available for use in scripts and playbooks.

</details>

<details>

<summary>The indicator exists in Cortex XSOAR and in Unit 42 Intel</summary>

The Cortex XSOAR result is displayed in a table. Click on the value to reach the Summary tab. The Summary tab presents information about the indicator stored in Cortex XSOAR. Click on the Unit 42 Intel tab to view Unit 42 data. From the Unit 42 Intel tab, you have the option to do the following:

* **Update**

  Updated Unit 42 Intel for the indicator is added to Cortex XSOAR. If the indicator is related to one or more Unit 42 threat intel objects already in Cortex XSOAR (brought in through the Unit 42 Feed integration), relationships are created in the database between the Unit 42 threat intel objects and the file indicator. No third-party enrichments are run on the indicator. We recommend using this option if, for security reasons, you do not want to expose the indicator to any third-party services.
* **Update & Enrich**

  Updated Unit 42 Intel for the indicator is added to Cortex XSOAR. If the indicator is related to one or more Unit 42 threat intel objects already in Cortex XSOAR (brought in through the Unit 42 Feed integration), relationships are created in the database between the Unit 42 threat intel objects and the file indicator. Your configured third-party enrichments are run on the indicator.

</details>

<details>

<summary>The indicator does not exist in Cortex XSOAR or in Unit 42 Intel</summary>

If the query was for an indicator type that is not an IP address, domain, URL, or SHA256 file hash OR if the query included a wildcard or a complex search, the search was performed on Cortex XSOAR data from the last 7 days. You can extend the date range to see if the indicator is in Cortex XSOAR but is older than 7 days.

![unit42-no-data.png](/files/yfjFZ20pdlvbyvY7xWHm)

</details>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/threat-intel-management/indicator-management/query-indicators-with-unit-42-intel-data.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
