Define observable-observable relationships
Define relationships between observables.
시작하기 전에
Role required: sn_sec_tisc.analyst
프로시저
- Navigate to .
- Click on Threat Intel Library icon on the workspace.
- Go to .
- Click New.
-
Complete the fields in the form as appropriate.
Field Description Source Observable Select and define the source object. Target Observable Select and define the target object. Relationship Type A description that provides more details and context about the relationship type. The available options are: Define the relationship direction whether it is direct or inverse.
- Inverse - This is the type of relationship between the observable and object.
- Direct - This is the type of relationship between the object and observable.
Basis For Correlation Name of the correlation rule based on which the system has identified as the related records of that observable. This rule is auto populated. - Click Submit.