Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Define indicator-indicator relationships

Define relationships between the indicator object and other Use the relationships objects to link together two observables or an observable and SDO to explain how they relate to each other..

Before you begin

Role required: sn_sec_tisc.analyst

Procedure

  1. Navigate to Workspaces > Threat Intelligence Security Center.

  2. Click on Threat Intel Library icon on the workspace.

  3. Go to Relationships > Indicator-Indicator.

  4. Click New.

  5. Complete the fields in the form as appropriate.

FieldDescription
DescriptionSpecifies the threat source from which this record is created.
DomainDefines the scope of the object record. The value in this field is auto populated.
Target IndicatorSelect and define the target indicator object.
Relationship TypeA description that provides more details and context about the relationship type. Define the relationship direction whether it is direct or inverse. - Inverse - This is the type of relationship between the observable and object. - Direct - This is the type of relationship between the object and observable.
Source IndicatorSelect and define the source object indicator.
  1. Click Submit.

Parent Topic:Relationships Objects