Inheritance in Threat Intelligence Director configurations

Inheritance in Threat Intelligence Director configurations is a hierarchical configuration mechanism that

  • creates indicators and observables as child objects when Threat Intelligence Director ingests intelligence data from a source,

  • ensures child objects automatically inherit Action and Publish settings from their parent configuration on creation, and

  • maintains parent-child relationships where indicators inherit from source configurations and observables inherit from parent indicators.

Inheritance relationships

The inheritance hierarchy follows these parent-child relationships:

  • An indicator inherits these settings from the parent source. An indicator can only have one parent source.

  • An observable inherits these settings from the parent indicators. An observable can have multiple parent indicators.

For more information, refer to: