---
title: "Tag Normalization | ThreatConnect"
slug: "tag-normalization"
description: "This article describes Tag normalization in ThreatConnect, including how to create and manage Tag normalization rules, view details for main Tags, and identify when a main Tag is applied to an object."
updated: 2025-03-18T10:45:29Z
published: 2025-03-18T10:45:29Z
---

> ## Documentation Index
> Fetch the complete documentation index at: https://knowledge.threatconnect.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Tag Normalization

## Overview

System Administrators can create Tag normalization rules in ThreatConnect® that convert one or more synonymous Tags to a main Tag. When a Tag normalization rule is enabled, existing Tags in all [owners](https://knowledge.threatconnect.com/docs/ownership-in-threatconnect) on the ThreatConnect instance that match one of the rule’s synonymous Tags are converted to the main Tag at that time, and new Tags created on the ThreatConnect instance that match one of the rule’s synonymous Tags are converted to the main Tag whenever they are applied to [Indicators, Groups](https://knowledge.threatconnect.com/docs/the-threatconnect-data-model), [Victims](https://knowledge.threatconnect.com/docs/create#creating-a-victim), and [Workflow Cases](https://knowledge.threatconnect.com/docs/workflow-cases). This feature simplifies the management and consolidation of Tags and makes it easier for analysts to categorize objects accurately and uniformly.

## Before You Start

### User Roles

- To create and manage Tag normalization rules, your user account must have a [System role](https://knowledge.threatconnect.com/docs/threatconnect-system-roles-and-permissions) of Administrator.
- To view main Tags on the **Browse** screen in owners to which you have access, your user account can have any [Organization role](https://knowledge.threatconnect.com/docs/organization-roles).
- To view the legacy **Details** screen for a main Tag in an owner to which you have access, your user account can have any Organization role.
- To identify main Tags applied to an object, your user account can have any Organization role.

## Tag Normalization Rules

### Creating and Enabling Tag Normalization Rules

1. Log into ThreatConnect with a System Administrator account.
2. Hover over **Settings**![Settings icon](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Settings%20icon.png)on the top navigation bar and select **System Settings**.
3. Select the **Tags**tab on the **System Settings** screen.
4. Retain the selection of **Normalization** from the menu on the left side of the **Tags** screen to access the **Normalization**screen (Figure 1). ![Figure%201_Tag%20Normalization_7.4.0](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Figure%201_Tag%20Normalization_7.4.0.png)
5. Click **+ New Rule**at the top right of the **Normalization** screen.
6. Fill out the fields on the **Tag Rule**window (Figure 2) as follows:  
![Figure 2_Tag Normalization_7.2.0](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Figure%202_Tag%20Normalization_7.2.0.png)
  - **Main Tag**: Enter the main Tag to which the synonymous Tags will be converted. If there are existing Tags that match part or all of the entered text, a menu with those Tags will be displayed. In this scenario, you can select a Tag from the menu to add it as the main Tag.NoteWhenever a main Tag is applied to an object, the Tag’s name will match the letter case used when it was entered on the **Tag Rule**window.
  - **Synonymous Tags**: Enter one or more Tags to convert to the main Tag. After entering each Tag, click **Add![Add Tag button](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Add%20Tag%20button.png)**or press **Enter**on your keyboard to add it to the list of synonymous Tags. Because Tag normalization rules do not maintain case sensitivity when searching for synonymous Tags, you can use any letter case when entering them. For example, if you enter “ransomware” as a synonymous Tag, any form of that Tag (e.g., Ransomware, RANSOMWARE, rAnSoMwArE, etc.) will be converted to the main Tag listed in the rule.ImportantYou cannot use [ATT&CK® Tags](https://knowledge.threatconnect.com/docs/attack-tags) as synonymous Tags in a Tag normalization rule.
  - **Enabled**: Select this checkbox to enable the Tag normalization rule. (See Step 8.) If you do not select this checkbox, you can still save the rule and enable it later, either by editing it, selecting the **Enabled** checkbox, and saving it again or by using the [**Enable All**](/docs/tag-normalization#enabling-all-tag-normalization-rules) button to enable all rules at one time.
7. Click **SAVE** on the **Tag Rule**window.ImportantThe main Tag in one Tag normalization rule cannot be a synonymous Tag in another rule. Similarly, a synonymous Tag in one Tag normalization rule cannot be a synonymous Tag in another rule. Attempting to save a Tag normalization rule that violates either of these conditions will cause an error message to be displayed in the **Tag Rule**window.
8. If you selected the **Enabled**checkbox on the **Tag Rule**window, the **Enable Rule**window (Figure 3) will be displayed after you click **SAVE**on the **Tag Rule**window. Click **Enable & Merge Tags**on the **Enable Rule**window to enable the Tag normalization rule and convert all existing synonymous Tags on the ThreatConnect instance to the main Tag.  
![Figure 3_Tag Normalization_7.2.0](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Figure%203_Tag%20Normalization_7.2.0.png)

WarningThe conversion process cannot be stopped once started, is irreversible, and applies to Tags in all owners on the ThreatConnect instance. As part of the conversion process, all existing synonymous Tags are replaced by the main Tag and removed from the ThreatConnect instance.

### Viewing Conversion Status

After you enable a Tag normalization rule, the **Status**column on the **Normalization**screen (Figure 1) will display the status of the conversion process. If the process is queued or in progress, a **Queued**status will be displayed. Once the process is complete, the number of synonymous Tags converted to the main Tag will be displayed (e.g., **7 items merged**). Click **Refresh** at the top right of the screen to refresh the **Status**column.

### Enabling All Tag Normalization Rules

To enable all Tag normalization rules at once and start the conversion process for each one, click **Enable All**at the top right of the **Normalization** screen (Figure 1), and then click **Enable & Merge**on the **Enable All** window.

### Disabling All Tag Normalization Rules

To disable all Tag normalization rules at once, click **Disable All**at the top right of the **Normalization**screen (Figure 1). All rules will be disabled immediately, and you will not be prompted for confirmation.

NoteDisabling a Tag normalization rule does not reverse the effects of the rule and restore previously converted synonymous Tags. Instead, it stops the rule from converting newly created Tags that match a synonymous Tag listed in the rule into the main Tag.

### Editing Tag Normalization Rules

Click **Edit![Pencil icon_Black](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Pencil%20icon_Black.png)**in the **Options**column of the **Normalization**screen (Figure 1) to edit a Tag normalization rule. If the rule is enabled, you will be prompted to restart the conversion process after saving your changes.

### Deleting Tag Normalization Rules

Click **Delete![Trash icon_Black](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Trash%20icon_Black.png)**in the **Options**column of the **Normalization**screen (Figure 1) to delete a Tag normalization rule. When you delete a rule, any newly created Tags that match a synonymous Tag listed in the rule will no longer be converted to the main Tag.

NoteDeleting a Tag normalization rule does not reverse the effects of the rule and restore previously converted synonymous Tags.

## Viewing Main Tag Details

### Browse Screen

When [viewing Tags](https://knowledge.threatconnect.com/docs/the-browse-screen#tags) on the [**Browse**screen](https://knowledge.threatconnect.com/docs/the-browse-screen), main Tags have a![Main Tag icon_Browse Screen](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Main%20Tag%20icon_Browse%20Screen.png)icon displayed to the left of their name in the **Summary**column. The number of synonymous Tags listed in the corresponding Tag normalization rule is displayed in the **Synonymous Tags**column. Click the number to view the synonymous Tags associated with the main Tag (Figure 4)

![Screenshot of a tag and its synonymous tags in the Browse screen. ](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Figure%204_Tag%20Normalization_7.8.2.png)

NoteTo view only main Tags on the **Browse**screen, turn on the **Advanced Search** toggle****above the search bar to switch to the [advanced search feature](https://knowledge.threatconnect.com/docs/running-advanced-searches-with-tql), ensure **Tags** is selected****in the dropdown to the right of the toggle, enter normalized = true into the search bar, and click **Search![Search drawer icon](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Search%20drawer%20icon.png)**to the right of the search bar or press **Enter**on your keyboard.

### Legacy Details Screen

On a main Tag’s [legacy **Details**screen](https://knowledge.threatconnect.com/docs/the-details-screen-legacy), all synonymous Tags listed in the corresponding Tag normalization rule are displayed on the **Synonymous Tags**card (Figure 5).

![Screenshot of synonymous tags.](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Figure%205_Tag%20Normalization_7.8.2.png)

## Identifying Main Tags Applied to Objects

On an object’s [**Details**screen](https://knowledge.threatconnect.com/docs/the-details-screen) and **[](https://knowledge.threatconnect.com/docs/the-details-drawer)** [](https://knowledge.threatconnect.com/docs/the-details-drawer)[**Details**drawer](https://knowledge.threatconnect.com/docs/the-details-drawer) [](https://knowledge.threatconnect.com/docs/the-details-drawer)**[](https://knowledge.threatconnect.com/docs/the-details-drawer)**, or while [viewing a Case](https://knowledge.threatconnect.com/docs/parts-of-a-case#viewing-a-case), main Tags have a![Main Tag icon_Details Screen](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Main%20Tag%20icon_Details%20Screen.png)icon displayed to the left of their name (Figure 6). This icon is also displayed when [applying Tags](https://knowledge.threatconnect.com/docs/applying-tags) to an object, under the **Standard Tags**section.

![Figure 6_Tag Normalization_7.2.0](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Figure%206_Tag%20Normalization_7.2.0.png)

NoteOn the legacy **Details**screen, main Tags are not denoted with the![Main Tag icon_Details Screen](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Main%20Tag%20icon_Details%20Screen.png)icon.

When you apply a newly created Tag to an object and it matches a synonymous Tag listed in a Tag normalization rule, it will be converted to the main Tag listed in the rule, and a message stating “One or more tags have been changed due to system tag normalization rules” will be displayed at the lower-left corner of the screen.

---

*ThreatConnect® is a registered trademark of ThreatConnect, Inc.* *MITRE ATT&CK® and ATT&CK® are registered trademarks of The MITRE Corporation.*

20155-01 v.01.C
