---
title: "Creating Threat Intelligence Data | ThreatConnect"
slug: "creating-threat-intelligence-data"
description: "This article provides an overview of creating individual threat intelligence data objects in ThreatConnect."
status: "update"
updated: 2026-01-11T15:26:49Z
published: 2026-01-11T15:26:49Z
canonical: "knowledge.threatconnect.com/creating-threat-intelligence-data"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://knowledge.threatconnect.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Creating Threat Intelligence Data

## Overview

You can quickly create individual [Indicators](https://knowledge.threatconnect.com/docs/the-threatconnect-data-model#indicators), [Groups](https://knowledge.threatconnect.com/docs/the-threatconnect-data-model#groups), [Intelligence Requirements (IRs)](https://knowledge.threatconnect.com/docs/the-threatconnect-data-model#intelligence-requirements), and [Victims](https://knowledge.threatconnect.com/docs/the-threatconnect-data-model#victims) in your [ThreatConnect® owners](https://knowledge.threatconnect.com/docs/ownership-in-threatconnect) on the following object-specific **Search** screens:

- [**Search: Indicators** screen](https://knowledge.threatconnect.com/docs/searching-indicators)
- [**Search: Groups** screen](https://knowledge.threatconnect.com/docs/searching-groups)
- [**Search: Intelligence Requirements** screen](https://knowledge.threatconnect.com/docs/searching-intelligence-requirements)
- [**Search: Victims** screen](https://knowledge.threatconnect.com/docs/searching-victims)

After you create a threat intelligence data object, its **[](https://knowledge.threatconnect.com/docs/the-details-screen)** [](https://knowledge.threatconnect.com/docs/the-details-screen)[**Details** screen](https://knowledge.threatconnect.com/docs/the-details-screen) [](https://knowledge.threatconnect.com/docs/the-details-screen)**[](https://knowledge.threatconnect.com/docs/the-details-screen)** will open, and you can begin investigating and contextualizing the object.

## In This Series

- *[Creating Indicators](https://knowledge.threatconnect.com/docs/creating-indicators)*: Learn how to create an Indicator.
- *[Creating Groups](https://knowledge.threatconnect.com/docs/creating-groups)*: Learn how to create a Group.
- *[Creating Victims](https://knowledge.threatconnect.com/docs/creating-victims)*: Learn how to create a Victim.
- *[Creating Intelligence Requirements](https://knowledge.threatconnect.com/docs/creating-intelligence-requirements)*: Learn how to create and configure an IR and view its preliminary results.

---

*ThreatConnect® is a registered trademark of ThreatConnect, Inc.*

20003-01 v.15.B

## Related

- [Structured Indicator Import](/structured-indicator-import.md)
- [Unstructured Indicator Import](/unstructured-indicator-import.md)
- [Signature Import](/signature-import.md)
- [Email Import](/email-import.md)
- [The ThreatConnect Data Model](/the-threatconnect-data-model.md)
- [The Details Screen](/the-details-screen.md)
