Identify indicator sources
Indicator sources are normally tracked automatically as part of the threat import process, but more sources can be manually added.
Before you begin
Role required: sn_ti.write
Procedure
Navigate to All > Threat Intelligence > IoC Repository > Indicators.
Click the indicator to which you want to add indicator sources.
Click the Indicator Sources related list.
Click Edit.
As needed, use the filters to locate the indicator source you want to associate with the IoC.
Using the slushbucket, add the indicator source to the Indicator Sources list.
Click Save.
Parent Topic:Indicators of compromise
Related topics
Add a related observable to an IoC
Add a related attack mode/method to an IoC