The ThreatIntelEntities table contains threat intelligence indicators, including indicators of compromise (IOCs) such as IP addresses, URLs, and file hashes.
Schema
Name
Description
Type
AdditionalFields
Additional fields associated with the indicator in dynamic format
Object
Confidence
Confidence score of the indicator (0-100)
Int32
Created
Date and time when the indicator was created
DateTime
Data
Raw indicator data in dynamic format
Object
Id
Unique identifier for the threat intelligence entity document
String
IsActive
Indicates whether the indicator is currently active
Boolean
LastUpdateMethod
Method used for the most recent update to the indicator
String
Modified
Date and time when the indicator was last modified
DateTime
ObservableKey
Observable type extracted from the pattern (e.g., ipv4-addr:value, domain-name:value, network-traffic:src_ref.value)
String
ObservableValue
Observable value extracted from the pattern (e.g., an IP address, domain, or URL)
String
Pattern
STIX pattern expression for the indicator (e.g., [ipv4-addr:value = ‘1.2.3.4’])
String
Revoked
Indicates whether the indicator has been revoked by its source
Boolean
SourceSystem
Source system that provided the threat intelligence entity
String
Tags
Tags associated with the indicator
Object
TenantId
Unique identifier of the tenant into which the data connector ingests data.
String
Type
Type of the record, indicating the source table name
String
ValidFrom
Date and time from which the indicator is considered valid
DateTime
ValidUntil
Date and time until which the indicator is considered valid