Indicators
Threat intel in the console holds indicators: IP addresses, domains, URLs, file hashes and email addresses, each with a type, severity, source, scope (one organization or all) and tags. Add them by hand, import a CSV or STIX bundle, or subscribe to a feed as an integration of type indicator feed.
Matching
- At ingest. Every event's entities are compared against the loaded indicators as it arrives. A hit produces an alert through an indicator-match detection without waiting for a scheduled rule.
- Retro-hunt. When a new indicator lands, the platform searches the full retention window for earlier matches. An indicator published today meets last week's logs.
Enrichment
During triage and in playbooks, XenXDR can query external reputation services for an indicator: VirusTotal for hashes, domains and URLs, AbuseIPDB for addresses. Enrichment is off until you add the service and its key in Settings › Integrations. The indicators sent to those services can in some cases be personal data; the subprocessors page lists them for that reason.
Rule interaction
Indicator matches respect suppressions and exceptions like any other detection. An indicator can be expired with a date so that a stale list does not keep firing.