Bring the complete public collection index into threat research
When the team starts a threat discussion, retrieve the paginated public collection set as a reference for follow-up.
Trigger
Channel Message Received
Triggered when a message is posted in a Slack channel (public, private, or multi-party IM). Does NOT match direct messages.
Action
Get Public Collections Paginated
Tool to retrieve all public Collections using pagination from IBM X-Force Exchange. Use when you need to access publicly available collections with pagination support. Returns a list of publicly accessible case files with pagination metadata.
Why this helps
Researchers can lose time finding whether relevant public case files exist across a large collection set.
- Uses pagination for broader public collection retrieval.
- Supports discussions that need a wider set of case-file references.
- Avoids relying on a latest-items-only view.
Setup
Build it in a few focused steps.
- 1Connect both Slack and IBM X-Force Exchange to Notis once.
- 2Create an automation through the portal or by asking Notis in plain language.
- 3Tell Notis to retrieve paginated public X-Force collections when a message arrives in the chosen threat channel.
- 4Choose the Slack channel message trigger and a channel for run reports.
- 5Test with a real message in the selected research channel.
Questions about this workflow
Why choose the paginated action?
It is intended to retrieve all public collections using pagination, with pagination metadata.
Does a Slack message filter need field mapping?
No. State the intended channel context in the plain-language prompt and select the Slack channel message trigger.
When this happens · Trigger
Do this · Action
Supported Triggers and Actions
Notis builds workflows that link Slack to IBM X-Force Exchange. A trigger fires from one place; an action lands in another.
Slack triggers
IBM X-Force Exchange actions
Recurring trigger
Notis starts this workflow on a schedule, such as daily, weekly, or during business hours.
Get Latest Public Collections
Tool to retrieve latest public Collections from IBM X-Force Exchange. Use when you need to access publicly available collections without pagination. For fetching all public collections, consider using the paginated endpoint instead.
Webhook trigger
Notis starts this workflow when an external tool or custom backend sends an HTTP request.
Get Public Collections Paginated
Tool to retrieve all public Collections using pagination from IBM X-Force Exchange. Use when you need to access publicly available collections with pagination support. Returns a list of publicly accessible case files with pagination metadata.
New Channel Created Trigger
Triggered when a new channel is created in Slack.
Get IPR Category List
Tool to retrieve the complete list of IP reputation categories from IBM X-Force Exchange. Use when you need to understand available IPR classification categories used by XFE.
Channel Message Received
Triggered when a message is posted in a Slack channel (public, private, or multi-party IM). Does NOT match direct messages.
Get URL Category List
Tool to retrieve the complete list of URL categories from IBM X-Force Exchange. Use when you need to understand available URL classification categories used by XFE.
Direct Message Received
Triggered when a new direct message (DM) is sent to a user in Slack. Catches all DMs across all DM channels.
Get User Profile Information
Tool to retrieve authenticated user's profile information from IBM X-Force Exchange. Use when you need to access user account details, membership statistics, or integration configurations.
Message Reaction Added
Triggered when a reaction is added to a message in Slack. Supports optional filtering by channel and emoji name.
Get Current API Version
Tool to retrieve current running API version information from IBM X-Force Exchange. Use when you need to check the API version, build number, or creation date.
Message Reaction Removed
Triggered when a reaction is removed from a message in Slack. Supports optional filtering by channel and emoji name.
Generate API Key and Password
Tool to generate a new API key and password pair for IBM X-Force Exchange authentication. Use when you need to create new credentials for API access. The generated credentials do not expire and can be used with Basic Authentication.
Reaction Added Trigger
DEPRECATED: use `SLACK_MESSAGE_REACTION_ADDED` instead. Triggered when a reaction is added to a message in Slack.
Connect any two apps with Notis in the middle.
Slack and IBM X-Force Exchange, or any other combination from 1,000+ integrations.
When this happens · Trigger
Do this · Action
Save your first hour today.
7-day trial of any paid plan, with 20$ of usage included.
No card. Works with personal or business IBM X-Force Exchange.