Define object-indicator relationships
Define relationships between the indicator object and other SDOs.
Before you begin
Role required: sn_sec_tisc.analyst
Procedure
Navigate to Workspaces > Threat Intelligence Security Center.
Click on Threat Intel Library icon on the workspace.
Go to Relationships > Object-Indicator.
Click New.
Complete the fields in the form as appropriate.
| Field | Description |
|---|---|
| Indicator | Select and define the indicator. |
| Object | Select and define the object. |
| Relationship Type | A description that provides more details and context about the relationship type. Define the relationship direction whether it is direct or inverse. - Inverse - This is the type of relationship between the observable and object. - Direct - This is the type of relationship between the object and observable. |
| Start Time | Specifies the time when the relationship is created. |
| Stop Time | Specifies the time when the relationship is stopped or removed. |
| Description | A brief description about the object relationships. |
- Click Submit.
Parent Topic:Relationships Objects