analysis custom stix indicator-type <type> enable

Prev Next

Enables the indicator type for STIX format intel feeds. Indicators contain a pattern that can be used to detect suspicious or malicious cyber activity. The malicious activity indicator type is enabled by default.

Syntax

[no]analysis custom stix indicator-type <type> enable

Use the ‘no’ form of the command to disable the indicator type.

Parameters

<type>

The indicator type can be:

  • malicious-activity

  • anonymization

  • compromised

  • attribution

  • unknown

Example

The following example enables the compromised indicator type.

hostname (config) # analysis custom stix indicator-type compromised enable

User role

Administrator or analyst or operator

Command mode

Enable

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Email Security — Server: Release 11.0.0

  • File Protect: Release 11.0.0

  • Malware Analysis: Release 11.0.0

  • Network Security: Release 11.0.0