Threat intelligence
Threat intelligence in Security Analytics offers the capability to integrate your threat intelligence feeds. Feeds comprise indicators of compromise (IOCs), which search for malicious indicators in your data by setting up threat intelligence monitors. These monitors generate findings and can send notifications when malicious IPs, domains, or hashes from the threat intelligence feeds match your data.
You can interact with threat intelligence in the following ways:
- Threat intelligence APsI: To configure threat intelligence using API operations, see Threat Intelligence APIs.
- OpenSearch Dashboards: To configure and use threat intelligence through the OpenSearch Dashboards interface, see Getting started.
Related articles
当前内容版权归 OpenSearch 或其关联方所有,如需对内容或内容相关联开源项目进行关注与资助,请访问 OpenSearch .