Skip to main content

IOCs Actions

Create IOC

Adding an IOC to a Case by filling in parameters in the step.

ParameterDescription
NameThe name of the IOC
TypeThe type of IOC
ValueThe value of the IOC
Link CasesThe Name and Id of the Case you want to add the IOC to
DescriptionA brief explanation of the IOC
Custom Fields (JSON Format)Add a Custom Field in JSON format. Please note that this applies only if you have manually added a custom record column to the subject table.
Advanced- Dedup TableThe selected table to evaluate the duplicated condition (Dedup Condition)against.
Advanced- Dedup ConditionThe duplicate condition to check wether to insert the record or not. When the condition is met, the record will not be inserted.
Advanced- Linked IOCsThe Name and ID of the IOC you want to link to this IOC
Advanced- Linked AlertsThe Name and ID of the Alert you want to link to this IOC.
Advanced- Linked AttachmentsThe Name and ID of the Attachment you want to link to this IOC.
Advanced- Linked TasksThe Name and ID of the Tasks you want to link to this IOC.
Advanced- Linked CasesThe Name and ID of a different Case you want link to this IOC
Thumbnail

Delete IOC

Deleting an IOC from a Case by filling in parameters in the step.

ParameterDescription
IOC IDThe ID of thw IOC: can be the id or the ioc_id field of the attachments
Thumbnail

Update IOC

Updating an already existing IOC in a Case by filling in the following parameters in the step. This action overwrites all of the IOC's data.

ParameterDescription
IOCThe IOC ID
NameThe updated Name of the IOC
TypeThe type of IOC
ValueThe value of the IOC
DescriptionA brief explanation explaining the IOC
Custom Fields(JSON Format)Add a Custom Field in JSON format. Please note that this applies only if you have manually added a custom record column to the subject table.
Thumbnail