Parameter | Description |
---|---|
Pattern | The pattern of the indicator. Example: [url:value = 'https://www.contoso.com'] .Note: the pattern must be unique. |
Pattern Type | The pattern type of the indicator. Example: url . |
Resource Group Name | The name of the resource group. The name is case insensitive. |
Source | The source of the indicator. |
Subscription ID | The ID of the target subscription. |
Workspace Name | The name of the workspace. |
Parameter | Description |
---|---|
Confidence | The confidence of the indicator. |
Defanged | Is the indicator defanged. |
Description | The description of the indicator. |
Display Name | The display name of the indicator. |
Etag | The Etag of the azure resource. |
Extensions | Extensions map. |
External ID | The external ID of the indicator. |
External Last Updated Time UTC | External last updated time in UTC. |
External References | A JSON list of references objects. Example:
|
Granular Markings | A JSON list of granular markings objects. Example:
|
Indicator Tags | A comma-separated list of indicator tags. |
Indicator Types | A comma-separated list of indicator types. |
Kill Chain Phases | A JSON list of kill chain phases objects. Example:
|
Labels | A comma-Separated list of labels. |
Language | The language of the indicator. |
Parsed Pattern | List of parsed patterns. Example:
|
Pattern Version | The pattern version of the indicator. |
Threat Types | A comma-separated list of threat types. |
Valid From | Valid from. |
Valid Until | Valid until. |