ti_indicators
Retrieve current threat intelligence indicators covering IPs, domains, URLs, file hashes, and email addresses. Choose a concise summary or raw STIX 2.1 for TIP/SIEM ingestion.
Instructions
Fetch the most recent Indicator Bundles from the Threat Intelligence feed.
Covers IPs, domains, URLs, file hashes and email addresses curated by eSentire's Threat Response Unit. Upstream refreshes hourly, and results are cached for that long, so calling this repeatedly inside an hour returns identical data.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| summarize | No | Flatten STIX bundles into a compact indicator list (default). Set False for raw STIX 2.1 suitable for TIP/SIEM ingestion. |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| result | Yes |