show analysis custom stix indicator-types

Prev Next

Displays the indicator types for STIX format intel feeds. Indicators contain a pattern that can be used to detect suspicious or malicious cyber activity. The malicious activity indicator type is enabled by default.

Syntax

show analysis custom stix indicator-types

Parameters

None

Example

The following example displays all the indicator types.

hostname (config) # show analysis custom stix indicator-types
List of supported STIX indicator types:
   1) malicious-activity
   2) anomalous-activity
   3) anonymization
   4) compromised
   5) attribution

User role

Administrator or analyst or operator

Command mode

Enable

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Email Security — Server: Release 11.0.0

  • File Protect: Release 11.0.0

  • Malware Analysis: Release 11.0.0

  • Network Security: Release 11.0.0