The "Last Modified" Date
  • 25 Nov 2024
  • 8 Minutes to read
  • Dark
    Light

The "Last Modified" Date

  • Dark
    Light

Article summary

Overview

When viewing Indicators, Groups, Intelligence Requirements (IRs), and Attributes in ThreatConnect®, the Last Modified field provides the date and time when the object was last modified. Similarly, the lastModified API field provides the date and time when an Indicator, Group, IR, or Attribute was last modified when using the ThreatConnect API to interact with these object types.

This article describes the various areas in ThreatConnect where you can view the date and time when an Indicator, Group, or Attribute was last modified. It also details actions you can perform when working with these object types and whether each action updates the Last Modified date.

Before You Start

User Roles

  • To view the date and time when Indicators, Groups, IRs, and Attributes in an Organization were last modified, your user account can have any Organization role.
  • To view the date and time when Indicators, Groups, and Attributes in a Community or Source were last modified, your user account can have any Community role except Banned.
  • To view the date and time when Indicators, Groups, IRs, and Attributes were last modified via the ThreatConnect API, your user account must have a System role of API User.

Viewing an Object’s “Last Modified” Date

ThreatConnect UI

There are five main areas in ThreatConnect where you can view the date and time when an object was last modified:

Hint
To view a log of changes made to an object in your Organization, including the date and time when the action was performed, navigate to the Activity tab of the Organization Settings screen. This tab is available only to users with an Organization role of Organization Administrator.

Browse Screen

While viewing Indicators, Groups, or IRs on the Browse screen, the results table includes a Modified column that provides the date when an object was last modified (Figure 1).

Figure 1_The Last Modified Date_7.1.0

 

Hint
You can use the FILTERS menu on the Browse screen to filter results by the date when they were last modified. Additionally, you can use the Browse screen’s advanced search feature to run a ThreatConnect Query Language (TQL) query that uses the lastModified TQL parameter to filter results based on the date when they were last modified.

Details Drawer

On the Details drawer for Indicators and Groups, the Last Modified field in the top portion of the drawer provides the date and time when the object was last modified in the owner listed in the drawer’s header. Figure 2 shows the Details drawer for an Indicator, along with the date and time when the Indicator was last modified in the owner named “Demo Organization.”

Graphical user interface, text, application, email, website  Description automatically generated

 

Note
The Details drawer’s Unified View option for Indicators includes a Last Modified field that provides the most recent date and time when an Indicator was last modified in any of its owners.

In addition, an Attribute’s Last Modified field on the Attributes card on the Details drawer provides the date and time when the Attribute was last modified (Figure 3).

Figure 3_The Last Modified Date_7.7.1

 

Note
If viewing the Details drawer for an Email, Signature, or Task Group, the Last Modified field for the Group is located at the top right of the drawer, and the date and time when each of the Group’s Attributes was last modified is located in the Last Modified column of the Attributes section on the drawer.

Details Screen

On the Details screen for Indicators, Groups, and IRs, the Last Modified field on the Details card provides the date and time when the object was last modified in the owner listed in the screen’s header (Figure 4).

Important
The new Details screen is not currently available for Email, Signature, and Task Groups. As such, you can view the Last Modified date for these Group types and their Attributes on the legacy Details screen only.

 

In addition, an Attribute’s Last Modified field on the Attributes card provides the date and time when the Attribute was last modified (Figure 5). The Attributes card is available on the Details screen for Indicators and Groups only.

 

Legacy Details Screen

On the legacy Details screen for Indicators and Groups, the Modified field on the Details card provides the date and time when the object was last modified in the owner listed at the top right of the screen (Figure 6).

Graphical user interface, application  Description automatically generated

 

In addition, an Attribute’s Last Updated field on the Attributes card provides the date and time when the Attribute was last modified (Figure 7).

 

Search Screen

When searching your ThreatConnect data on the Search screen, the search results table includes a Last Modified column that provides the date and time when an object was last modified in the owner listed in the Owner column (Figure 8).

Figure 8_The Last Modified Date_7.7.1

 

ThreatConnect API

When using the ThreatConnect API to interact with Indicators, Groups, IRs, and Attributes, the lastModified API field provides the date and time when an object was last modified. The v3 API includes the lastModified API field for Indicators, Groups, IRs, and Attributes; the v2 API includes the lastModified API field for Indicators and Attributes only.

Note
For Case Attributes, you can view the date and time when they were last modified using the v3 API. However, you cannot view this date and time in the ThreatConnect UI.

Updating an Object’s “Last Modified” Date

Indicators

Table 1 details the actions you can perform when working with Indicators and whether each one updates the date and time when an Indicator was last modified.

 

Action(s)Applies to Which Indicator Type(s)?Updates "Last Modified" Date?
Applying or removing Security LabelsAllYes1, 2
Associating Groups or Indicators to an IndicatorAllYes
Associating Cases or Artifacts to an IndicatorAllNo3
Dissociating Groups or Indicators from an IndicatorAllNo2
Dissociating Cases or Artifacts from an IndicatorAllNo3
Updating objects associated to an IndicatorAllNo
Creating, updating, or deleting Description or Source Attributes with or without the Default checkbox selectedAllYes
Creating or updating AttributesAllYes1
Deleting AttributesAllYes
Creating posts via the Add New Comment card of an Indicator’s Details screen or deleting posts added or linked to an IndicatorAllNo
Applying or removing TagsAllYes
Following or unfollowing an IndicatorAllNo
Adding a Task to an IndicatorAllNo
Updating or deleting a Task added to an IndicatorAllNo
Reporting false positives or deleting false positive reports for an IndicatorAllNo
Reporting observations for an IndicatorAllNo
Updating an Indicator’s Threat RatingAllYes
Updating an Indicator’s Confidence RatingAllYes
ThreatConnect updates an Indicator’s ThreatAssess scoreAllNo
Updating an Indicator's StatusAllYes
Turning the CAL Status Lock on or offAllYes
Marking an Indicator as privateAllYes
Reimporting an existing IndicatorAllYes
Creating, updating, or deleting File OccurrencesFileYes1, 2
Updating a File’s behavior modelFileNo
Adding or removing a file hashFileYes
Adding, updating, or removing a File Indicator’s size valueFileYes
Turning the DNS resolution tracking feature on or offHostYes1, 2
Turning the WHOIS feature on or offHostYes1, 2

1 Performing this action on the legacy Details screen will not update the Last Modified date.
2 Performing this action via the ThreatConnect v3 API will update the Last Modified date; however, performing this action via the ThreatConnect v2 API will not update the Last Modified date.
3 Performing this action via the ThreatConnect v3 API will update the Last Modified date; however, this action may not be performed using the ThreatConnect v2 API, as it does not support Workflow-related features.

Groups

Table 2 details the actions you can perform when working with Groups and whether each one updates the date and time when a Group was last modified.

 

Action(s)Applies to Which Group Type(s)?Updates "Last Modified" Date?
Applying or removing Security LabelsAllYes
Associating Groups, Indicators, Victim Assets, Cases, or Artifacts to a GroupAllYes
Dissociating Groups, Indicators, Victim Assets, Cases, or Artifacts from a GroupAllYes
Updating objects associated to a GroupAllNo
Creating, updating, or deleting Description or Source Attributes with or without the Default checkbox selectedAllYes
Creating, updating, or deleting AttributesAllYes
Creating posts via the Add New Comment card of a Group’s Details screenAllYes
Deleting posts added or linked to a GroupAllNo1
Applying or removing TagsAllYes
Following or unfollowing a GroupAllNo
Adding a Task to a GroupAllYes
Updating or deleting a Task added to a GroupAllNo2
Updating a Group's Intel RatingAllYes
Contributing a Group to a Community or SourceAllNo
Copying a Group from a Community to an OrganizationAllNo3
Publishing a GroupAllYes
Updating a Group’s summaryAllYes
Generating a PDF report of a GroupAll Group types except Document, Email, Signature, and TaskNo
Adding an Adversary assetAdversaryYes
Deleting an Adversary assetAdversaryNo
Enabling or disabling a TrackAdversaryNo
Track results are found for an AdversaryAdversaryNo
Adding, updating, or removing a Campaign’s First Seen dateCampaignYes
Updating the file name of the file corresponding to a DocumentDocumentYes
Downloading the file corresponding to a DocumentDocumentNo
Uploading a file to a DocumentDocumentYes
Updating the analysis for an Email (i.e., updating the Body, From field, Header, or Subject of the email corresponding to the Group)EmailYes
Adding, updating, or removing an Event’s Event DateEventYes
Adding or updating an Event’s StatusEventYes
Adding, updating, or removing an Incident’s Event DateIncidentYes
Adding or updating an Incident’s StatusIncidentYes
Downloading the file corresponding to a ReportReportNo
Uploading a file to a ReportReportYes
Adding, updating, or removing a Report’s Publish DateReportYes
Downloading a Signature’s file contentsSignatureNo
Importing a new Signature fileSignatureYes
Updating a Signature file’s name, type, or contentsSignatureYes
Adding or removing Task AssigneesTaskYes
Adding or removing users to whom a Task is to be escalatedTaskYes
Adding or updating a Task’s StatusTaskYes
Adding, updating, or removing a Task’s Due DateTaskYes
Adding, updating, or removing a Task’s Escalation TimeTaskYes
Adding, updating, or removing a Task’s Reminder TimeTaskYes

1 Performing this action on the legacy Details screen will update the Last Modified date.
2 If updating a Task added to a Group, the Last Modified date for the Group to which the Task was added will not be updated, but the Last Modified date for the Task will be updated.
3 The Last Modified date for the Group that exists in the Community will not be updated; the Last Modified date for the copy of the Group created in the Organization will match the Date Added date.

Intelligence Requirements

Table 3 details the actions you can perform when working with IRs and whether each one updates the date and time when an IR was last modified.

 

Action(s)Updates “Last Modified” Date?
Associating Groups, Indicators, Victim Assets, Artifacts, or Cases to an IRYes
Dissociating Groups, Indicators, Victim Assets, Artifacts, or Cases from an IRYes
Updating objects associated to an IRNo
Adding or updating the IR's default Description AttributeYes
Updating an IR's subtypeYes
Updating an IR's categoryYes
Applying or removing TagsYes
Following or unfollowing an IRNo
Updating an IR's summaryYes
Updating an IR's keyword queryYes
Resetting archived and false results for an IRYes
Retrieving results for an IRYes
Associating a result to an IRYes
Archiving a result for an IRNo
Marking a result for an IR as a false resultNo

Attributes

Table 4 details the actions you can perform when working with Attributes and whether each one updates the date and time when an Attribute was last modified.

 

Action(s)Updates "Last Modified" Date?
Applying or removing Security LabelsYes
Creating, updating, or removing an Attribute’s SourceYes
Updating an Attribute’s valueYes
Saving an Attribute’s Source so that it can be reused by the same ownerNo1
Selecting or clearing the Default checkbox for Description and Source AttributesYes

1 Performing this action on the legacy Details screen will update the Last Modified date.


ThreatConnect® is a registered trademark of ThreatConnect, Inc.

20132-01 v.04.B


Was this article helpful?