Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Identify indicator sources

Indicator sources are normally tracked automatically as part of the threat import process, but more sources can be manually added.

Before you begin

Role required: sn_ti.write

Procedure

  1. Navigate to All > Threat Intelligence > IoC Repository > Indicators.

  2. Click the indicator to which you want to add indicator sources.

  3. Click the Indicator Sources related list.

  4. Click Edit.

  5. As needed, use the filters to locate the indicator source you want to associate with the IoC.

  6. Using the slushbucket, add the indicator source to the Indicator Sources list.

  7. Click Save.

Parent Topic:Indicators of compromise

Related topics

View an IoC

Add a related observable to an IoC

Add a related attack mode/method to an IoC

Identify associated indicator types

Add associated tasks to an IoC