Threat intel investigation through XQL

XTI is integrated into the Cortex Query Language (XQL) system, empowering you to create investigations and hunt queries using the full depth of the XTI intelligence library.

You can query threat intel indicators and threat objects through the XQL Search Portal by navigating to Investigation & Response → Search → Query Builder.

The following threat intel XQL datasets are available:

Dataset name Description
threat_intel_indicators Contains all active threat intel indicators with their attributes.
threat_intel_threat_actors Contains all threat intel actors with their attributes.
threat_intel_malware Contains all threat intel malware families with their attributes.
threat_intel_relationships Describes associations between threat objects (threat actors, malware families) and indicators.
issue_to_indicator Correlates threat intel data with issues data.

Select the Schema tab to see all fields available for each dataset.

Because XTI datasets are holistic, stateful representations rather than time-bound logs, the Time frame filter is disabled for these datasets.

Related links

For general information about XQL, see Cortex XSIAM XQL.

Using XTI datasets in correlation rules

Using XTI datasets in correlation rules is not supported. Contact Palo Alto Networks if you have any questions.