---
title: Intelligence Objects Event Category
slug: Xd3c-intelligence-object-events
docTags: 
createdAt: 2026-08-25T12:57:04.367Z
---

An Intelligence Object is a threat intelligence entity surfaced in the [Intelligence Browser](docId:05UQcn5rINZDxddSrktMY). It is a structured record of something known to matter in a threat context: an indicator of compromise, a malware family, a named campaign, a vulnerability, a threat actor, or a piece of adversary infrastructure.

The Intelligence Object category connects the objects in the Intelligence Browser to your Identifiers and your Tenant Feed. When enabled on an Identifier, a match against an Intelligence Object surfaces an event in your feed, so exposures flagged by third-party risk lists appear alongside your other events.

![](https://api.archbee.com/api/optimize/wtmLmyh6YG71yn5qVtkMM/Tgz542KVHwRgdYQSFr4wf_image.png)

Intelligence Objects are also available through the [Flare API](https://api.docs.flare.io/api-reference/tokens/endpoints/generate) using the `intelligence_object` event type on the `Tenants`, `Identifiers`, and `Identifier Groups` endpoints.&#x20;

***

## Viewing Intelligence Object Events&#x20;

Intelligence Object Events can be viewed either in Global Search or in the Tenant Feed by selecting the Intelligence Objects event type.&#x20;

::Image[]{src="https://api.archbee.com/api/optimize/wtmLmyh6YG71yn5qVtkMM/4R128DBsyW77ZjQJEc4if_image.png" size="80" isUploading="false" width="1298" height="1276" darkWidth="1298" darkHeight="1276" position="flex-start" showCaption="false"}

### Event Details

Each Intelligence Object Event includes the following data:

- **Summary:** The Summary tab shows the event severity, metadata showing the object type, source, provider and relevant dates. A Confidence Score is also included from each of the sources. Click **View** to see additional details about the Intelligence Object. 

::Image[]{src="https://api.archbee.com/api/optimize/wtmLmyh6YG71yn5qVtkMM/f7ekPHK6ryn4LqD0eQXhx_upload.png" size="90" width="1258" height="808" isUploading="false" darkWidth="1258" darkHeight="808" position="flex-start" showCaption="false" indent="1"}

- **Severity:** The Severity tab shows how the event was scored and which Severity Rules were applied.&#x20;

:::hint{type="info" indent="1"}
Every event in this category is assigned an initial severity of <font color="#F97316">`High`</font>. To change the severity for these events, you can create a Custom Severity Rule or change the severity of the default Flare Rule. See [Severity Rules](docId\:LtSDxTP9nCx7-FOhtDSMK) for details.
:::

- **Advanced:** The Advanced tab provides complete raw data for the event for additional investigation.

***

## Configuration

Follow these steps to get full value from the Intelligence Objects surfaced for your organization.

::::WorkflowBlock
:::WorkflowBlockItem
**Select the Intelligence Object category for an Identifier**

The Intelligence Object category is enabled during Identifier configuration.

- Create a new Identifier or edit an existing one.
- Select **Intelligence Object** as one of the categories. 
- Use **Severity Filters** to define which severities to include for this Identifier. All Intelligence Object events are assigned an initial severity of <font color="#F97316">`High`</font>. To customize severity classification, see [Severity Rules](docId\:LtSDxTP9nCx7-FOhtDSMK).
- Optionally, use **Add to group&#x20;**&#x74;o organize the Identifier alongside related assets.

::Image[]{src="https://api.archbee.com/api/optimize/wtmLmyh6YG71yn5qVtkMM/DQr7IU56soyIcUXKGfbwN_image.png" size="80" isUploading="false" width="998" height="1306" darkWidth="998" darkHeight="1306" position="flex-start" showCaption="false" indent="1"}
:::

:::WorkflowBlockItem
**Configure alerting**

Once the Identifier is set up, use [Alert Central](docId\:eQFoSNLszdT49_kdW6Xts) to send alerts to the right stakeholders.

1. Create a new alert, and set the **Identifier Scope** to the Identifier created for Intelligence Objects.
2. Under **Categories**, select **Intelligence Object**. 
3. Use **Severity Filters** to restrict the alert to the severities that warrant interruption. 
4. Configure **Time Settings** to control alert frequency and timing. 
5. Select an **Alert Channel** for delivery. 


::Image[]{src="https://api.archbee.com/api/optimize/wtmLmyh6YG71yn5qVtkMM/W2hBrimQjKL4ObpKpaDyX_image.png" size="80" isUploading="false" width="982" height="1190" darkWidth="982" darkHeight="1190" position="flex-start" showCaption="false" indent="1"}
:::

:::WorkflowBlockItem
**Take action**

From the Tenant Feed, you can act on an event using the following actions: 

- **Mark as remediated:** Indicate that the exposure has been addressed.
- **Ignore:** Remove the Event from your active feed when it is not relevant to you.
- **Edit:** Modify the event's classification.
- **Add to report:** Include the event in a report for internal or client-facing distribution.

::Image[]{src="https://api.archbee.com/api/optimize/wtmLmyh6YG71yn5qVtkMM/ZOuWQL4XwL24hObyrihCB_image.png" size="100" isUploading="false" width="1382" height="312" darkWidth="1382" darkHeight="312" showCaption="false" indent="1"}
:::
::::

***

## Building an Investigation Workflow

An Intelligence Object event serves as the entry point for an investigation rather than the conclusion. The value comes from what you do next, which is confirming the match, understanding the threat behind it, and responding appropriately. The steps below cover two workflows, one that uses the [Cyber Threat Intelligence (CTI module)](docId\:rrHH7-7ULNlXqtkG-iJTc) and one that works from the Tenant Feed alone.

::::Tabs
:::Tab{title="With the CTI Module"}
1. **Triage in the Tenant Feed**
   Confirm which Identifier matched and how critical the match is.

::Image[]{src="https://api.archbee.com/api/optimize/wtmLmyh6YG71yn5qVtkMM/w1WJXg0YqKowDrM1X-eDT_upload.png" size="100" width="1456" height="800" isUploading="false" darkWidth="1456" darkHeight="800" showCaption="false" indent="1"}

2. **Use the object confidence score to weigh your response**&#x20;
   A high-confidence match supported by strong evidence supports faster action than a low-confidence one.&#x20;
3. **Pivot to the Intelligence Browser**
   View the Intelligence Object in the [Intelligence Browser](docId:05UQcn5rINZDxddSrktMY) to see additional details about IOCs, malware families, threat actors, campaigns, and intrusion sets. Open the matched Intelligence Object to see its sources, metadata, and relationships to other objects. This is where you learn whether the indicator is tied to an active campaign, known malware, or an attributed actor.

::Image[]{src="https://api.archbee.com/api/optimize/wtmLmyh6YG71yn5qVtkMM/WsNWx4N4ZxGbI85Hs8nq7_upload.png" size="100" width="2048" height="807" isUploading="false" darkWidth="2048" darkHeight="807" showCaption="false" indent="1"}

4. **Act and close the loop**&#x20;
   Take the appropriate action in your environment, then use Mark as remediated or Ignore in the feed so your team has an accurate picture of what has been handled.

::Image[]{src="https://api.archbee.com/api/optimize/wtmLmyh6YG71yn5qVtkMM/sPDM26hCwVcghWrlxT4QL_upload.png" size="80" width="1066" height="480" isUploading="false" darkWidth="1066" darkHeight="480" position="flex-start" showCaption="false" indent="1"}
:::

:::Tab{title="Without the CTI Module"}
1. **Triage in the Tenant Feed&#x20;**&#xA;Confirm which Identifier matched and how critical the match is.

::Image[]{src="https://api.archbee.com/api/optimize/wtmLmyh6YG71yn5qVtkMM/OBKgJgoqB3o2yR-TfXcfW_upload.png" size="100" width="1456" height="800" isUploading="false" darkWidth="1456" darkHeight="800" showCaption="false" indent="1"}

2. **Use the object confidence score to weigh your response**
   A high-confidence match supported by strong evidence supports faster action than a low-confidence one.
3. **Act and close the loop**
   Take the appropriate action in your environment, then use Mark as remediated or Ignore in the feed so your team has an accurate picture of what has been handled.

::Image[]{src="https://api.archbee.com/api/optimize/wtmLmyh6YG71yn5qVtkMM/2bE1as1amogawCEs5Hshc_upload.png" size="90" width="1066" height="480" isUploading="false" darkWidth="1066" darkHeight="480" position="flex-start" showCaption="false" indent="1"}
:::
::::

****

****

