Use Case TIM Best Practice

Use Case Builder markdown

Details

IDincident_usecasetimbestpractice
CLI Nameusecasetimbestpractice
Typemarkdown
Version-1
RequiredNo
Read OnlyNo
Use as KPINo
SearchableNo

Associated Incident Types

{
    "associatedToAll": false,
    "associatedTypes": [
        "Use Case Builder"
    ],
    "caseInsensitive": true,
    "cliName": "usecasetimbestpractice",
    "closeForm": false,
    "content": true,
    "editForm": true,
    "group": 0,
    "hidden": false,
    "id": "incident_usecasetimbestpractice",
    "isReadOnly": false,
    "locked": false,
    "name": "Use Case TIM Best Practice",
    "neverSetAsRequired": false,
    "openEnded": false,
    "ownerOnly": false,
    "required": false,
    "sla": 0,
    "system": false,
    "template": "# Threat Intel Management\n## Manually Add Indicators to the Exclusion List\nFrom the Exclusion List page, you can manually add a single indicator or define indicators using a regular expression (regex) or CIDR.\n\n### Regex\n\nA regular expression enables you to identify a sequence of characters in an unknown string. The following example would identify www.demisto.com: [A-Za-z0-9!@#$%\\.\u0026]*demisto[A-Za-z0-9!@#$%\\.\u0026]*.\n\n### CIDR\nClassless inter-domain routing (CIDR) enables you to define a range of IP addresses. For example, the IPv4 block 192.168.100.0/22 represents the 1024 IPv4 addresses from 192.168.100.0 to 192.168.103.255.\n\n## Indicator Management: [TIM (Cortex XSOAR 6.13)](https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/6.13/Cortex-XSOAR-Threat-Intel-Management-Guide/Exclusion-List) or [TIM (Cortex XSOAR 8 Cloud)](https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-Cloud-Documentation/Delete-and-exclude-indicators) or [TIM (Cortex XSOAR 8.7 On-prem)](https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8.7/Cortex-XSOAR-On-prem-Documentation/Delete-and-exclude-indicators)",
    "threshold": 72,
    "type": "markdown",
    "unmapped": false,
    "unsearchable": true,
    "useAsKpi": false,
    "version": -1,
    "fromVersion": "6.8.0"
}