AI | Entity Extraction#

Entities that were ingested on Incoming feeds or created after uploading a file may contain information that would ideally be captured in further Entities. You can have AI extract Entities from the information contained in Entities in your platform, so you don’t have to do this manually.

The AI will identify new Entities in the ingested Entities’ Title and Description fields, as well as in their Tags. Check the list below to see which Entity types can be extracted with this feature.

Text consideration limit

Only the first 75000 characters of the relevant fields are exported to the AI when using this feature.

Extracted Entity types

When extracting Entities, the follow types are recognized by the AI:

  • Attack Pattern

  • Campaign

  • Course of Action

  • Identity

  • Infrastructure

  • Intrusion Set

  • Location

  • Malware

  • Threat Actor

  • Tool

  • Vulnerability

The following Entities types are extracted based on pattern recognition:

  • ASN

  • CCE

  • CVE

  • CWE

  • Domains

  • Email Addresses

  • Hashes

  • IP Addresses

  • MAC Addresses

  • URIs

The newly created Entities will be related to the Entity they were extracted from.

  1. From the left sidebar, go to Search icon Search and then go to the Entities tab.

  2. (Optional) Enter a search query to find the Entity you’d like to extract from.

  3. In the row of the Entity you’d like to extract from, open the More options, line of three dots arranged vertically menu.

  4. From the Entity menu, select Extract.
    A modal will open showing you the progress of the extraction.
    Once the extraction finished, the modal will show you the Entities it found.
    If you had closed the modal, you can reopen it from Notifications > Updates.

  5. Check the Entities the AI extracted.
    If needed, you can:

    • Change the Entities’ types.

    • Change the Entities’ names.

    • Select Re-scan if you think the AI missed significant Entities.

  6. Select the Entities you’d like to create.

  7. (Optional) Select the Settings Settings to change:

    • The source of the extracted Entities.

    • The TLP of the extracted Entities.

    • Whether the extracted Entities should be related to the Entity they were extracted from.

    • If the extracted Entities need to be added to a Collection dataset.

    • Which Tags should be applied to the extracted Entities.

    • If the Tags applied to the orginal Entity should also be applied to the Extracted entities.

  8. Select Create.

You can also initiate Entity Extraction from: