Enables the indicator type for STIX format intel feeds. Indicators contain a pattern that can be used to detect suspicious or malicious cyber activity. The malicious activity indicator type is enabled by default.
Syntax
[no]analysis custom stix indicator-type <type> enable
Use the ‘no’ form of the command to disable the indicator type.
Parameters
<type>
The indicator type can be:
malicious-activity
anonymization
compromised
attribution
unknown
Example
The following example enables the compromised indicator type.
hostname (config) # analysis custom stix indicator-type compromised enable
User role
Administrator or analyst or operator
Command mode
Enable
Supported appliances
This command is supported on the following appliances running the specified releases or later:
Email Security — Server: Release 11.0.0
File Protect: Release 11.0.0
Malware Analysis: Release 11.0.0
Network Security: Release 11.0.0