Threat intel investigation through XQL ↗
XTI is integrated into the Cortex Query Language (XQL) system, empowering you to create investigations and hunt queries using the full depth of the XTI intelligence library.
You can query threat intel indicators and threat objects through the XQL Search Portal by navigating to Investigation & Response → Search → Query Builder.
The following threat intel XQL datasets are available:
| Dataset name | Description |
|---|---|
| threat_intel_indicators | Contains all active threat intel indicators with their attributes. |
| threat_intel_threat_actors | Contains all threat intel actors with their attributes. |
| threat_intel_malware | Contains all threat intel malware families with their attributes. |
| threat_intel_relationships | Describes associations between threat objects (threat actors, malware families) and indicators. |
| issue_to_indicator | Correlates threat intel data with issues data. |
Select the Schema tab to see all fields available for each dataset.
Because XTI datasets are holistic, stateful representations rather than time-bound logs, the Time frame filter is disabled for these datasets.
Related links
For general information about XQL, see Cortex XSIAM XQL.
Using XTI datasets in correlation rules
Using XTI datasets in correlation rules is not supported. Contact Palo Alto Networks if you have any questions.