Netskope LogoNetskope Logo
  • Security Services
  • AI Services
  • Networking Services
  • Analytics Services
  • Integrations
  • getting-started.svgGetting Started
    • Support
    • Community
    • Netskope.com
    © 2026 All Rights Reserved. Netskope Inc.
    Home
    Netskope Cloud Exchange
    Threat Exchange Module

    Threat Exchange Module

    Threat Exchange is a rules-based engine for collecting and sharing indicators related to file hashes of malicious software (malware), file hashes of files used in Netskope DLP policy for absolute matching, or URLs used by plugged in systems for policy enforcement of restricted or allowed access.

    Click play to learn how to set up Threat Exchange.

    Threat Exchange Global Settings

    Only write-access users can change Threat Exchange Global Settings. Go to Settings > Threat Exchange. If the same IoC value is reported from different sources, then based on the reconciliation criteria, Threat Exchange will decide which IoC metadata should be kept and which will be ignored.

    Reconciliation Criterias

    Possible Reconciliation Criterias include:

    • Always Overrides: If this criteria is selected, the latest IoC metadata will be kept in case of IoC Duplication.
    • Never Overrides: If this criteria is selected, the oldest IoC metadata will be kept in case of IoC Duplication.
    • Highest Severity Source Override: If this criteria is selected, the highest severity source’s IoC metadata will be kept in case of IoC Duplication.

    Click play to watch a video.

    IoC(s) Retraction

    To enable IoC retraction from Cloud Exchange:

    1. Go to Setting > Threat Exchange.
    2. Enable the IoC(s) Retraction toggle and enter the Retraction Interval.
    1. Click Save.
    • Configure 3rd-party Threat Exchange Plugins
    • View Configured Threat Exchange Plugins
    • Update Configured Threat Exchange Plugins
    • Manage Threat Exchange Business Rules and IoC Sharing
    • Configure your Netskope Tenant for Threat Exchange File Hash Sharing
    • Manage Tags
    • Threat Exchange Custom Plugin Developers Guide
    In this Topic
    • Threat Exchange Module