Factors that affect the action taken
Factors that affect the action taken are system conditions that determine when the system takes action and what action the system takes when it detects traffic that matches a Threat Intelligence Director observable.
Action determination factors
The system considers these factors when determining actions:
-
Features like Security Intelligence take action before Threat Intelligence Director does. For details, refer to Threat Intelligence Director - Cloud-Delivered Firewall Management Center action prioritization.
-
Generally, the action configured for an observable (which may differ from the action configured for its parent indicator or source) is the action that will be taken.
-
Because Structured Threat Information eXpression (STIX) sources can contain complex indicators, the Action setting for the source can be set only to Monitor. However, individual simple indicators or observables contained in a STIX feed or file can be set to Block.
-
Action settings for indicators and observables can be inherited or individually configured to override inheritance. Refer to Inheritance in Threat Intelligence Director configurations and Edit Threat Intelligence Director actions at the source, indicator, or observable Level.
-
Traffic that might otherwise be actionable might be on a Do Not Block list. For details, refer to Add Threat Intelligence Director observables to a Do Not Block list.
-
The configured action is taken for both partially- and fully-realized incidents.
-
An incident based on a complex indicator can be partially blocked. This can occur if the indicator includes both monitored and blocked observations.
-
The actions the system takes are affected when publishing is paused. Refer to Pausing publishing and Pause or publish Threat Intelligence Director data at the source, indicator, or observable Level.
-
Pausing the Threat Intelligence Director feature prevents all actions. After you resume the feature, actionable data may be different from before. For details, refer to Pause Threat Intelligence Director and purge Threat Intelligence Director data from elements.