Agentic Assistant Threat Intel (TI) Agent works with Extended Threat Intelligence (XTI) and Threat Intel Management (TIM).
* If you have XTI only enabled, the TI Agent reads from and writes to the XTI dataset. Only the actions listed below are supported.
* If you have both XTI and TIM enabled side-by-side:
* The TI Agent reads from the XTI dataset. Only the actions listed below are supported.
* The TI Agent writes to both XTI and TIM datasets. Only the actions listed below are supported for XTI.
* If you disable XTI, the TI Agent reads from and writes to the TIM dataset.
## TI Agent actions supported by XTI
The TI Agent can perform various read and write actions. The TI Agent can perform the following actions for XTI:
| **Action** | **Example prompt** |
| ----------------------------------------------------------------------- | ----------------------------------------------- |
| List indicators | Show me the most recent malicious IP indicators |
| List indicator relationships | Show me relationships with 183.132.45.96 |
| Update Indicator | Update 1.1.1.10 to verdict Benign |
| <p>Enrich Domain</p><p>Enrich File</p><p>Enrich IP</p><p>Enrich URL</p> | Show me information about 192.43.254.85 |
Enrich CVE is currently not supported.
**Related links**
For general information and best practices related to enabling and using Agentic Assistant chat, see [Agentic Assistant chat](../../agentic-assistant-chat).
<br>