For the complete documentation index, see llms.txt. This page is also available as Markdown.
Cortex XSOAR 6.13

Indicator Fields

Create and configure fields for indicators.

Indicator fields are used to add specific indicator information to indicators. When you create a custom indicator field, you can add it to the indicator layout to which you associate the field. You can then Map Custom Indicator Fields to the relevant indicator type. You can also add an Indicator Field Trigger Script that checks for field changes and enables you to automatically take action.

Note

Cortex XSOAR IOC fields are based on the STIX 2.1 specifications. For more information, see Indicator Fields Structure.

Last updated

Was this helpful?