cortex_analyze_observable
Analyze security observables like IPs, domains, and URLs by running all applicable analyzers to collect aggregated results with taxonomy summaries for threat investigation.
Instructions
Run ALL applicable analyzers against an observable and collect aggregated results with taxonomy summary
Input Schema
TableJSON Schema
| Name | Required | Description | Default |
|---|---|---|---|
| dataType | Yes | The observable data type (ip, domain, hash, url, etc.) | |
| data | Yes | The observable value | |
| tlp | No | Traffic Light Protocol level (default: 2/AMBER) | |
| pap | No | Permissible Actions Protocol level (default: 2) | |
| timeout | No | Timeout in seconds per analyzer (default: 300) |