--- title: "Pivoting on Data | ThreatConnect" slug: "pivoting-on-data" description: "This article describes how to pivot from Indicators, Groups, Tags, and Attributes in ThreatConnect." tags: ["Connecting Data"] updated: 2024-12-03T13:39:07Z published: 2024-12-03T13:39:07Z canonical: "knowledge.threatconnect.com/pivoting-on-data" --- > ## Documentation Index > Fetch the complete documentation index at: https://knowledge.threatconnect.com/llms.txt > Use this file to discover all available pages before exploring further. # Pivoting on Data ## Overview Pivoting is an analytic transition in which you move from one entity—Indicators and Groups in the [ThreatConnect® Data Model](https://knowledge.threatconnect.com/docs/the-threatconnect-data-model), as well as [Tags](https://knowledge.threatconnect.com/docs/applying-tags) and [Attributes](https://knowledge.threatconnect.com/docs/creating-attributes)—to an associated entity as defined by the [Diamond Model](https://knowledge.threatconnect.com/docs/the-diamond-model). Through pivoting, you can explore relationships and find correlations between entities in a contiguous manner. ## Before You Start ### User Roles - To pivot from Indicators, Groups, Tags, and Attributes in an Organization, your user account can have any [Organization role](https://knowledge.threatconnect.com/docs/organization-roles). - To pivot from Indicators, Groups, Tags, and Attributes in a Community or Source, your user account can have any [Community role](https://knowledge.threatconnect.com/docs/community-roles) except Banned. ## Pivoting From Indicators and Groups There are three areas in ThreatConnect where you can pivot from Indicators and Groups: - the **[](/docs/pivoting-on-data#_Details_Drawer)**[](/docs/pivoting-on-data#_Details_Drawer)[**Details** drawer](/docs/pivoting-on-data#details-drawer)[](/docs/pivoting-on-data#_Details_Drawer)**[](/docs/pivoting-on-data#_Details_Drawer)** - the [**Details** screen](/docs/pivoting-on-data#details-screen) - the [legacy **Details** screen](/docs/pivoting-on-data#legacy-details-screen) ImportantYou can pivot from Email, Signature, and Group types on the **Details** drawer and legacy **Details** screen only. ### Details Drawer Follow these steps to pivot from an Indicator or a Group on the **Details** drawer: 1. [Open the **Details** drawer](https://knowledge.threatconnect.com/docs/the-details-drawer#accessing-the-details-drawer-for-threat-intelligence-data) for an Indicator or a Group. 2. Click the **⋯** menu in the **Details** drawer header and select **Pivot**. The **Browse** screen will open and display the following elements (Figure 1): NoteIf viewing the **[](https://knowledge.threatconnect.com/docs/the-details-drawer#email-signature-and-task)**[](https://knowledge.threatconnect.com/docs/the-details-drawer#email-signature-and-task)[**Details** drawer for an Email, Signature, or Task Group](https://knowledge.threatconnect.com/docs/the-details-drawer#email-signature-and-task)[](https://knowledge.threatconnect.com/docs/the-details-drawer#email-signature-and-task)**[](https://knowledge.threatconnect.com/docs/the-details-drawer#email-signature-and-task)**,  click the **⋮** menu in the **Details** drawer header and select **Pivot** to pivot from the Group.![Graphical user interface, application Description automatically generated](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Figure%201_Pivoting%20on%20Data_7.7.1.png) - A results table with all Groups (if you selected **Pivot** on an Indicator’s **Details** drawer) or Indicators (if you selected **Pivot** on a Group’s **Details** drawer) [associated](https://knowledge.threatconnect.com/docs/associations) to the object you pivoted from. - A gray rectangle containing the summary of the object you pivoted from. This element will be displayed above the results table. ### Details Screen Follow these steps to pivot from an Indicator or a Group on the **Details** screen: 1. [Open the **Details** screen](https://knowledge.threatconnect.com/docs/the-details-screen#viewing-the-details-screen) for an Indicator or a Group. 2. Click the **⋯** menu in the **Details** screen header and select **Pivot**. The **Browse**screen will open and display the following elements: - A results table with all Groups (if you selected **Pivot** on an Indicator’s **Details** screen) or Indicators (if you selected **Pivot** on a Group’s **Details** screen) [associated](https://knowledge.threatconnect.com/docs/associations) to the object you pivoted from. - A gray rectangle containing the summary of the object you pivoted from. This element will be displayed above the results table. ### Legacy Details Screen Follow these steps to pivot from an Indicator or a Group on the legacy **Details** screen: 1. [Open the legacy **Details** screen](https://knowledge.threatconnect.com/docs/the-details-screen-legacy#viewing-the-legacy-details-screen) for an Indicator or a Group. 2. Click **Pivot** in the legacy **Details** screen header. The **Browse**screen will open and display the following elements: - A results table with all Groups (if you clicked the **Pivot** button on an Indicator’s legacy **Details** screen) or Indicators (if you clicked the **Pivot** button on a Group’s legacy **Details** screen) [associated](https://knowledge.threatconnect.com/docs/associations) to the object you pivoted from. - A gray rectangle containing the summary of the object you pivoted from. This element will be displayed above the results table. ## Pivoting From Tags Follow these steps to pivot from Tag: 1. [Open the **Details** drawer](https://knowledge.threatconnect.com/docs/the-details-drawer#accessing-the-details-drawer-for-threat-intelligence-data) for a Tag. 2. Click the **⋮** menu in the **Details** drawer header and select **Pivot**. 3. After selecting **Pivot**, select whether to pivot on **Indicators** or **Groups**. The **Browse**screen will open and display the following elements: - A results table with all Indicators or Groups the Tag is [applied](https://knowledge.threatconnect.com/docs/applying-tags) to. - A gray rectangle containing the name of the Tag you pivoted from. This element will be displayed above the results table. ## Pivoting From Attributes You can pivot from an Attribute on the **[](/docs/pivoting-on-data#_Details_Screen)**[](/docs/pivoting-on-data#_Details_Screen)[**Details** screen](/docs/pivoting-on-data#details-screen1)[](/docs/pivoting-on-data#_Details_Screen)**[](/docs/pivoting-on-data#_Details_Screen)** and [legacy **Details** screen](/docs/pivoting-on-data#legacy-details-screen1) for the Indicator, Group, or Victim the Attribute belongs to. ### Details Screen Follow these steps to pivot from an Attribute added to an Indicator or a Group on the **Details** screen: 1. [Open the **Details** screen](https://knowledge.threatconnect.com/docs/the-details-screen#viewing-the-details-screen) for an Indicator or a Group.ImportantYou can pivot from Attributes added to Email, Signature, and Task Groups or Victims on the legacy **Details** screen only. 2. Expand an Attribute on the **Attributes** card. If the maximum character length for the Attribute’s type is 500 or less, the **Pivot** button will be available for the Attribute (Figure 2). ![Figure%202_Pivoting%20on%20Data_7.4.0](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Figure%202_Pivoting%20on%20Data_7.7.1.png) 3. Click **Pivot** button to pivot from the Attribute The **Browse** screen will open and display the following elements: - A results table with all objects that have a matching Attribute (that is, an Attribute whose type and value match the type and value of the Attribute you pivoted from). - A gray rectangle containing the type and value of the Attribute you pivoted from. This element will be displayed above the results table. ### Legacy Details Screen Follow these steps to pivot from an Attribute added to an Indicator, Group, or Victim on the legacy **Details** screen: 1. [Open the legacy **Details** screen](https://knowledge.threatconnect.com/docs/the-details-screen-legacy#viewing-the-legacy-details-screen) for an Indicator, Group, or Victim. 2. Locate an Attribute with the **Pivot**![Pivot icon_Blue](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Pivot%20icon_Blue.png)icon on the **Attributes** card (Figure 3). This icon will be available for an Attribute if the maximum character length for the Attribute’s type is 500 or less. ![Figure 3_Pivoting on Data_7.1.1](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Figure%203_Pivoting%20on%20Data_7.7.1.png) 3. Click **Pivot**![Pivot icon_Blue](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Pivot%20icon_Blue.png)to pivot from the Attribute. The **Browse** screen will open and display the following elements: - A results table with all objects that have a matching Attribute (that is, an Attribute whose type and value match the type and value of the Attribute you pivoted from). - A gray rectangle containing the type and value of the Attribute you pivoted from. This element will be displayed above the results table --- *ThreatConnect® is a registered trademark of ThreatConnect, Inc.* 20034-01 v.09.E ## Related - [Applying Tags](/applying-tags.md) - [Associations](/associations.md) - [Attributes](/attributes.md) - [The Details Screen](/the-details-screen.md) - [The Diamond Model](/the-diamond-model.md) - [The ThreatConnect Data Model](/the-threatconnect-data-model.md)