> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/detect-and-respond-to-threats/threat-intel-management/indicator-configuration/configure-threat-intel-feed-integrations.md).

# Configure Threat Intel feed integrations

You can download and install Threat Intel content packs, including the following Threat Intel integrations such as:

* MITRE ATT\&CK
* Unit 42 Feed
* Unit 42 Intelligence
* AlienVault
* AWS

{% hint style="info" %}

### Note

If you have a TIM licens,e you can set up unlimited feeds. If not, you are limited to 5 active feeds and 100 indicators. For more information, see [Understand Cortex XSOAR licenses](/cortex-xsoar-8-on-prem/8.8/learn-about-cortex-xsoar/get-started-with-cortex-xsoar/understand-cortex-xsoar-licenses.md).

Some third-party services (such as Whois and VirusTotal) enforce strict rate limits based on the source IP address. If you encounter quota management issues, we recommend running them on an engine. This routes the traffic through your own private network, ensuring the external service sees a unique, dedicated IP address exclusive to your organization.
{% endhint %}

How to configure threat intel feed integrations

1. Go to Marketplace and install the relevant Threat Intel content pack.
2. Configure the Threat Intel integration by going to **Settings** → **Settings & Info** → **Integrations** → **Instances**, search for your integration, and click **Add Instance**.

   The following table is a non-exhaustive list of the most common feed integration parameters. Each feed integration may have parameters unique to that integration. Read the documentation for specific feed integrations for more details.

   | Parameter                          | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
   | ---------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
   | Fetches indicators                 | <p>Select this option for the integration instance to fetch indicators.</p><p>Some integrations can fetch indicators or incidents. Select the relevant option for what you need to fetch in the instance.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
   | URL                                | The URL of the feed.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
   | Feed Fetch Interval                | When the integration instance should fetch indicators from the feed.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
   | Indicator verdict                  | The indicator verdict that will apply to all indicators fetched from this integration instance. See [Indicator verdict](/cortex-xsoar-8-on-prem/8.8/detect-and-respond-to-threats/threat-intel-management/indicator-investigation/indicator-verdict.md).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
   | Source reliability                 | <p>The reliability of the source that provides the threat intelligence data.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Important</strong></p><p>To use custom field mapping with this integration instance, set the source reliability value higher than in other active enrichment integration instances. If another instance has a higher source reliability, the custom mappings for this integration instance will not populate in the dashboard.</p></div>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
   | Indicator Expiration Method        | <p>The method by which to expire indicators from this integration instance. The default expiration method is the interval configured for the indicator type to which this indicator belongs.</p><ul><li>Indicator Type: The expiration method defined for the indicator type to which this indicator belongs (interval or never).</li><li>Time Interval: Expires indicators from this instance after the specified time interval, in days or hours.</li><li>Never Expire: Indicators from this instance never expire.</li><li><p>When removed from the feed: When the indicators are removed from the feed they are expired in the system.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>Some feeds only provide information about new indicators and do not specify when indicators are removed. Indicators from these feeds cannot be automatically expired on removal.</p><p>If a feed's expiration method is set to <strong>When removed from the feed</strong>, indicators that are removed from the feed immediately expire. Note that if the feed is disabled, its expiration method reverts to that of the indicator type (time-based).</p><p>Time-based expiration is set according to feed reliability. If the same indicator appears on multiple feeds, the feed with the highest reliability determines the indicator's expiration time. If multiple feeds have the same reliability, the last feed to add or modify the indicator determines its expiration time.</p><p>Example:</p><ul><li>An indicator was initially fetched by Feed A, then by Feed B.</li><li>Both feeds have the same reliability.</li><li>Feed B's indicators are set to expire <strong>When removed from the feed</strong>.</li><li>Feed B is now disabled.</li></ul><p>After Feed B is disabled, the indicator's expiration method reverts to that of the indicator type (for example, expire after 7 days). However, if Feed A then modifies the indicator (or removes and re-adds it), the expiration method changes back to Feed A's settings.</p></div></li></ul> |
   | Bypass exclusion list              | When selected, the exclusion list is ignored for indicators from this feed. This means that if an indicator from this feed is on the exclusion list, the indicator might still be added to the system.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
   | Trust any certificate (not secure) | When selected, certificates are not checked.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
   | Use system proxy settings          | Runs the integration instance using the proxy server (HTTP or HTTPS) when an engine is selected.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
   | Do not use in CLI by default       | Excludes this integration instance when running a generic command that uses all available integrations.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.8/detect-and-respond-to-threats/threat-intel-management/indicator-configuration/configure-threat-intel-feed-integrations.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
