{ "associatedToAll": false, "associatedTypes": [ "Use Case Builder" ], "caseInsensitive": true, "cliName": "usecasetimbestpractice", "closeForm": false, "content": true, "editForm": true, "group": 0, "hidden": false, "id": "incident_usecasetimbestpractice", "isReadOnly": false, "locked": false, "name": "Use Case TIM Best Practice", "neverSetAsRequired": false, "openEnded": false, "ownerOnly": false, "required": false, "sla": 0, "system": false, "template": "# Threat Intel Management\n## Manually Add Indicators to the Exclusion List\nFrom the Exclusion List page, you can manually add a single indicator or define indicators using a regular expression (regex) or CIDR.\n\n### Regex\n\nA regular expression enables you to identify a sequence of characters in an unknown string. The following example would identify www.demisto.com: [A-Za-z0-9!@#$%\\.\u0026]*demisto[A-Za-z0-9!@#$%\\.\u0026]*.\n\n### CIDR\nClassless inter-domain routing (CIDR) enables you to define a range of IP addresses. For example, the IPv4 block 192.168.100.0/22 represents the 1024 IPv4 addresses from 192.168.100.0 to 192.168.103.255.\n\n## Indicator Management: [TIM (Cortex XSOAR 6.13)](https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/6.13/Cortex-XSOAR-Threat-Intel-Management-Guide/Exclusion-List) or [TIM (Cortex XSOAR 8 Cloud)](https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-Cloud-Documentation/Delete-and-exclude-indicators) or [TIM (Cortex XSOAR 8.7 On-prem)](https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8.7/Cortex-XSOAR-On-prem-Documentation/Delete-and-exclude-indicators)", "threshold": 72, "type": "markdown", "unmapped": false, "unsearchable": true, "useAsKpi": false, "version": -1, "fromVersion": "6.8.0" }