Skip to content
Notis

Bring the complete public collection index into threat research

When the team starts a threat discussion, retrieve the paginated public collection set as a reference for follow-up.

Trigger

Channel Message Received

Triggered when a message is posted in a Slack channel (public, private, or multi-party IM). Does NOT match direct messages.

Action

Get Public Collections Paginated

Tool to retrieve all public Collections using pagination from IBM X-Force Exchange. Use when you need to access publicly available collections with pagination support. Returns a list of publicly accessible case files with pagination metadata.

Why this helps

Researchers can lose time finding whether relevant public case files exist across a large collection set.

  • Uses pagination for broader public collection retrieval.
  • Supports discussions that need a wider set of case-file references.
  • Avoids relying on a latest-items-only view.

Setup

Build it in a few focused steps.

  • 1Connect both Slack and IBM X-Force Exchange to Notis once.
  • 2Create an automation through the portal or by asking Notis in plain language.
  • 3Tell Notis to retrieve paginated public X-Force collections when a message arrives in the chosen threat channel.
  • 4Choose the Slack channel message trigger and a channel for run reports.
  • 5Test with a real message in the selected research channel.

Questions about this workflow

Why choose the paginated action?

It is intended to retrieve all public collections using pagination, with pagination metadata.

Does a Slack message filter need field mapping?

No. State the intended channel context in the plain-language prompt and select the Slack channel message trigger.

When this happens · Trigger

Do this · Action

Supported Triggers and Actions

Notis builds workflows that link Slack to IBM X-Force Exchange. A trigger fires from one place; an action lands in another.

Slack triggers

IBM X-Force Exchange actions

Recurring trigger

Notis starts this workflow on a schedule, such as daily, weekly, or during business hours.

TriggerScheduled

Get Latest Public Collections

Tool to retrieve latest public Collections from IBM X-Force Exchange. Use when you need to access publicly available collections without pagination. For fetching all public collections, consider using the paginated endpoint instead.

ActionInstant

Webhook trigger

Notis starts this workflow when an external tool or custom backend sends an HTTP request.

TriggerInstant

Get Public Collections Paginated

Tool to retrieve all public Collections using pagination from IBM X-Force Exchange. Use when you need to access publicly available collections with pagination support. Returns a list of publicly accessible case files with pagination metadata.

ActionInstant

New Channel Created Trigger

Triggered when a new channel is created in Slack.

TriggerInstant

Get IPR Category List

Tool to retrieve the complete list of IP reputation categories from IBM X-Force Exchange. Use when you need to understand available IPR classification categories used by XFE.

ActionInstant

Channel Message Received

Triggered when a message is posted in a Slack channel (public, private, or multi-party IM). Does NOT match direct messages.

TriggerInstant

Get URL Category List

Tool to retrieve the complete list of URL categories from IBM X-Force Exchange. Use when you need to understand available URL classification categories used by XFE.

ActionInstant

Direct Message Received

Triggered when a new direct message (DM) is sent to a user in Slack. Catches all DMs across all DM channels.

TriggerInstant

Get User Profile Information

Tool to retrieve authenticated user's profile information from IBM X-Force Exchange. Use when you need to access user account details, membership statistics, or integration configurations.

ActionInstant

Message Reaction Added

Triggered when a reaction is added to a message in Slack. Supports optional filtering by channel and emoji name.

TriggerInstant

Get Current API Version

Tool to retrieve current running API version information from IBM X-Force Exchange. Use when you need to check the API version, build number, or creation date.

ActionInstant

Message Reaction Removed

Triggered when a reaction is removed from a message in Slack. Supports optional filtering by channel and emoji name.

TriggerInstant

Generate API Key and Password

Tool to generate a new API key and password pair for IBM X-Force Exchange authentication. Use when you need to create new credentials for API access. The generated credentials do not expire and can be used with Basic Authentication.

ActionInstant

Reaction Added Trigger

DEPRECATED: use `SLACK_MESSAGE_REACTION_ADDED` instead. Triggered when a reaction is added to a message in Slack.

TriggerInstant

Connect any two apps with Notis in the middle.

Slack and IBM X-Force Exchange, or any other combination from 1,000+ integrations.

When this happens · Trigger

Do this · Action

Save your first hour today.

7-day trial of any paid plan, with 20$ of usage included.
No card. Works with personal or business IBM X-Force Exchange.