Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Define indicator sightings

Define sightings that denote that an indicator was seen.

Before you begin

Role required: sn_ti.admin

Procedure

  1. Navigate to All > Threat Intelligence > IoC Repository > Indicator Sightings.

  2. Click New.

  3. Complete the fields in the form as appropriate.

    FieldDescription
    IndicatorIdentifies the indicator. Search and select the indicator.
    CountThe number of times the object was seen.
    First SeenThe time that this object first seen performing malicious activities.
    Last SeenThe time that this object was last seen performing malicious activities.
    SourceSpecifies the threat source from which this record is created.
    DescriptionA description that provides more details and context about the indicator sighting, potentially including its purpose and its key characteristics.
    Source IDUnique identifier for this object in the threat source.
    Is Summary 
    Created Time in SourceSpecifies the time the object is created in the source.
    Modified Time in SourceSpecifies the time the object is modified in the source.
  4. Click Submit.

What to do next

Click any of the following related lists to view additional information about objects associated with the indicator sighting.

Related ListsDescription
External ReferencesLists external references which refer to non-STIX information. This property is used to provide one or more external object identifiers.
IdentitiesList of identities associated with this object.
Observed DataLists observed data associated with this object.

Parent Topic:Sightings