---
title: "Searching in ThreatConnect"
slug: "searching-in-threatconnect"
description: "This article provides an overview of the Search screen in ThreatConnect, which is where you can search all object types in your dataset, browse your dataset by object type, and run bulk Indicator searches from an uploaded file."
tags: ["Getting Started", "Viewing Data"]
status: "update"
updated: 2026-01-10T20:06:35Z
published: 2026-01-10T20:06:35Z
canonical: "knowledge.threatconnect.com/searching-in-threatconnect"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://knowledge.threatconnect.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Searching in ThreatConnect

## Overview

The **Search** screen in ThreatConnect® provides a single location to search and browse your data. You can search all object types in your ThreatConnect dataset using keywords or phrases, or you can browse threat intelligence data by object type and filter those data to a usable and relevant subset based on details like name/summary, object subtype, owner, and metadata such as Tags, Security Labels, and Attributes.

When searching all object types, the ThreatConnect search engine searches an object’s summary and metadata to form a relevance-ordered result set based on how closely each result matches the search query. As you review search results, you can use filters to fine-tune the result set and analyze the most relevant data. When browsing your data by object type, you can search and filter objects using basic search queries or using advanced search queries written in [ThreatConnect Query Language (TQL)](https://knowledge.threatconnect.com/docs/threatconnect-query-language-tql). Depending on the object type, you can perform additional actions such as exporting data to a comma-separated values (CSV) file or deleting objects in bulk.

In addition to searching and browsing your data, you can run bulk Indicator searches by uploading files to the ThreatConnect search engine. Each time you upload a file, the ThreatConnect search engine parses the file for Indicators and returns a result set containing known and unknown Indicators. While viewing the results set, you can consolidate duplicate known Indicators into a single row for improved efficiency and focus. You can also perform bulk actions such as adding Indicators to your Organization, adding Tags to Indicators, and exporting Indicators to a CSV file.

## In This Series

- [*Searching All Object Types*](https://knowledge.threatconnect.com/docs/searching-all-object-types): Learn how to search all object types in your ThreatConnect dataset on the **Search: All Object Types** screen.
- [*Viewing Search Results for All Object Types*](https://knowledge.threatconnect.com/docs/viewing-search-results-for-all-object-types): Learn how to view, sort, and filter search results on the **Search: All Object Types** screen.
- [*Bulk Searching Indicators*](https://knowledge.threatconnect.com/docs/bulk-searching-indicators): Learn how to run a bulk Indicator search on an uploaded file from the **Search: All Object Types** screen and view, sort, and filter the corresponding search results.
- *[Searching by Object Type](https://knowledge.threatconnect.com/docs/searching-by-object-type)*: Learn how to use the object filters on the **Search** screen to search and browse threat intelligence data by object type.
  - *[Searching Groups](https://knowledge.threatconnect.com/docs/searching-groups)*: Learn how to use the **Search: Groups** screen to view, search, filter, export, delete, and analyze Groups.
  - *[Searching Indicators](https://knowledge.threatconnect.com/docs/searching-indicators)*: Learn how to use the **Search: Indicators** screen to view, search, filter, export, delete, and analyze Indicators.
  - *[Searching Intelligence Requirements](https://knowledge.threatconnect.com/docs/searching-intelligence-requirements)*: Learn how to use the **Search: Intelligence Requirements** screen to view, search, filter, and analyze Intelligence Requirements.
  - *[Searching Tags](https://knowledge.threatconnect.com/docs/searching-tags)*: Learn how to use the **Search: Tags** screen to view search, filter, and delete standard Tags and analyze standard Tags and ATT&CK® Tags.
  - *[Searching Victim Assets](https://knowledge.threatconnect.com/docs/searching-victim-assets)*: Learn how to use the **Search: Victim Assets** screen to view, search, filter, delete, and analyze Victim Assets.
  - *[Searching Victims](https://knowledge.threatconnect.com/docs/searching-victims)*: Learn how to use the **Search: Victims** screen to view, search, filter, delete, and analyze Victims.
  - *[Saved Search Queries](https://knowledge.threatconnect.com/docs/saved-search-queries)*: Learn how to save, view, edit, delete, and run saved queries when using the object filters on the **Search** screen.
- [*Searching in ThreatConnect (Legacy)*](https://knowledge.threatconnect.com/docs/searching-in-threatconnect-legacy) : Learn how to use the legacy **Search** drawer to search your ThreatConnect data and view search results.
  - [*Searching Your Data (Legacy)*](https://knowledge.threatconnect.com/docs/searching-your-data-legacy): Learn how to search your ThreatConnect data with the **Search** drawer.
  - [*Search Filters (Legacy)*](https://knowledge.threatconnect.com/docs/search-filters-legacy): Learn how to filter search results on the **Search** drawer.
  - [*Search Results (Legacy)*](https://knowledge.threatconnect.com/docs/search-results-legacy): Learn about the types of search results returned on the **Search** drawer.

---

*ThreatConnect® is a registered trademark of ThreatConnect, Inc.* *MITRE ATT&CK® and ATT&CK® are registered trademarks of The MITRE Corporation.*

20075-01 v.10.B
