Define object-observable relationships
Define relationships between SDOs and the observable object (SCO).
始める前に
Role required: sn_sec_tisc.analyst
手順
- Navigate to .
- Click on Threat Intel Library icon on the workspace.
- Go to .
- Click New.
-
Complete the fields in the form as appropriate.
Field Description Observable Select and define the observable. Object Select and define the object. Relationship Type A description that provides more details and context about the relationship type. Define the relationship direction whether it is direct or inverse.
- Inverse - This is the type of relationship between the observable and object.
- Direct - This is the type of relationship between the object and observable.
Start Time Specifies the time when the relationship is created. Stop Time Specifies the time when the relationship is stopped or removed. Description A brief description about the object relationships. - Click Submit.