The Details Screen
  • 27 Mar 2024
  • 16 Minutes to read
  • Dark
    Light

The Details Screen

  • Dark
    Light

Article Summary

Important
This article covers the new Details screen introduced in ThreatConnect version 7.0. For more information on the legacy Details screen, which may include some functionality not yet available on the new Details screen, see The Details Screen (Legacy).

Overview

The Details screen is the main screen where you can view and manage information and metadata for the following ThreatConnect® object types: Intelligence Requirements, Indicators, Groups, Tags, Tracks, and Victims. Although data displayed on the Details screen depends on the type of object you are viewing, some of the most commonly displayed information includes Attributes added to the object, Security Labels and Tags applied to the object, a list of objects associated to the object you are viewing, and insights from CAL™. This screen also provides shortcuts to various ThreatConnect features, such as reporting, Threat Graph, and the ATT&CK® Visualizer.

Before You Start

Minimum Role(s)
  • Organization role of Read Only User (for viewing data on an object’s Details screen)
  • Organization role of Standard User (for editing data on an object’s Details screen and deleting objects)
Prerequisites

Viewing the Details Screen

  1. On the top navigation bar, hover the cursor over Browse and select an object category (i.e., Intelligence Requirements (IR), Indicators, Groups, Tags, Tracks, Victims, or Victim Assets) or type (e.g., Host, Adversary) to display a results table containing objects of the selected category or type on the Browse screen.
  2. Hover over an object’s entry in the table on the Browse screen and click one of the following icons displayed in its Summary cell to display the object's Details screen:
    • View full detailsView full details_Browse: Click this icon to open the object’s Details screen in the current browser tab.
    • View full details in new tabView full details in new tab icon: Click this icon to open the object’s Details screen in a new browser tab.

Alternatively, click on an object’s entry in the table on the Browse screen to display its Details drawer, and then click the View full detailsView full details_Details drawericon at the upper-right corner of the drawer to display the object's Details screen.

Note
The Details drawer is not available for Intelligence Requirements at this time.
Note
For a Victim Asset, no icons are displayed when hovering over its entry in the table on the Browse screen. Instead, you must click on its entry in the table to display its Details drawer and then click the View full detailsIcon  Description automatically generatedicon at the upper-right corner of the drawer. This will display the Details screen for the Victim to which the Victim Asset belongs.

New Details Screen View

The new Details screen view is currently available for Intelligence Requirements, all Indicator types, and the following Group types: Adversary, Attack Pattern, Campaign, Course of Action, Document, Event, Incident, Intrusion Set, Malware, Report, Tactic, Threat, Tool, Vulnerability Groups. It is not available for Email, Signature, and Task Groups; Tags; Tracks; and Victims.

Figure 1 shows the Overview tab of the new Details screen for an Address Indicator (71.6.135.131), and Figure 2 shows the Overview tab of the new Details screen for an Adversary Group (Bad Guy).

Figure 1_The Details Screen_7.1.0

 

Figure 2_The Details Screen_7.1.0

 

New Details Screen Header

Intelligence Requirements

For descriptions of each section and element included in the header of the Details screen for Intelligence Requirements, see the “Details Screen Header” section of Viewing Intelligence Requirement Details.

Indicators

The new Details screen for Indicators (Figure 1) includes the following sections and elements in its header:

  • Browse /<Object name>: This section is located at the upper-left corner of the screen and includes a link to view all Indicators on the Browse screen. It also displays the name of the Indicator whose Details screen you are viewing.
  • Object icon and name: This section displays the Indicator’s name and an icon corresponding to its Indicator type.
  • <Object type> | <Owner type: Owner name>: This section displays the Indicator’s type followed by the type and name of the owner to which it belongs. If the Indicator belongs to multiple owners, a dropdown from which you can select the owner in which you want to view the object’s Details screen will be displayed.
  • Revert to Legacy View: Click the Revert to Legacy View button to display the Overview tab of the legacy Details screen for the Indicator in the current browser tab.
  • Explore in Graph: Click the Explore In Graph button to view the Indicator in Threat Graph.
  • OptionsIcon  Description automatically generated: Click this button to display a menu with the following options:
    • Pivot: Select this option to pivot to a list of all associated intelligence for the Indicator.
    • Change Status to Active/Inactive: Select this option to set the Indicator Status to Active (if it is currently set to Inactive) or Inactive (if it is currently set to Active).
    • Enable/Disable CAL Status Lock: Select this option to allow (Enable) or prevent (Disable) CAL from changing the Indicator Status.
    • Add to Exclusion List: Select this option to add the Indicator to the Indicator Exclusion List corresponding to its Indicator type.
    • Delete: Select this option to delete the Indicator.
  • Follow Item: Toggle this setting on to receive alerts and updates on changes to the object. After this setting is toggled on, use the bellIcon  Description automatically generatedicons to set the desired notification priority, where Low is oneIcon  Description automatically generatedicon, Medium is twoIcon  Description automatically generatedicons, and High is threeIcon  Description automatically generatedicons.
  • Indicator Status: This section displays the Indicator Status and whether it was set by ThreatConnect or CAL. If an Indicator is added to an Exclusion List, the text “⊘ On Exclusion List” will be displayed to the right of the Indicator Status.
Important
The Add to Exclusion List option will be displayed for Organization and System Administrators only on ThreatConnect instances where this functionality is enabled in the system settings. If you add an Indicator to an Exclusion List using this method, the only way to remove it from the Exclusion List is via the Organization Config screen, as detailed in the “Adding an Indicator to an Exclusion List from the Details Screen” section of Creating Indicator Exclusion Lists.

Groups

The new Details screen for Groups (Figure 2) includes the following sections and elements in its header:

  • Browse /<Object name>: This section is located at the top left of the screen and includes a link to view all Groups on the Browse screen. It also includes the name of the Group whose Details screen you are viewing.
  • Object icon and name: This section displays the Group’s name and an icon corresponding to its Group type. In addition, an EditIcon  Description automatically generatedbutton will be displayed to the right of the Group’s name that, when clicked, allows you to edit the name.
  • <Object type> | <Owner type: Owner name>: This section displays the Group’s type followed by the type and name of the owner to which it belongs.
  • Revert to Legacy View: Click the Revert to Legacy View button to display the Overview tab of the legacy Details screen for the Group in the current browser tab.
  • Create Custom Report: Click the Create Custom Reportbutton to display a menu with the following options:
  • Visual Analysis: Click the Visual Analysis button to display a menu with the following options:
  • OptionsIcon  Description automatically generated: Click this button to display a menu with the following options:
    • Pivot: Select this option to pivot to a list of all associated intelligence for the Group.
    • Download PDF: Select this option to generate a PDF document of the Group.
    • Delete: Select this option to delete the Group.
  • Follow Item: Toggle this setting on to receive alerts and updates on changes to the object. After this setting is toggled on, use the bellIcon  Description automatically generatedicons to set the desired notification priority, where Low is oneIcon  Description automatically generatedicon, Medium is twoIcon  Description automatically generatedicons, and High is threeIcon  Description automatically generatedicons.
  • Intel Rating: This section is where you can view the number of Upvoteand DownvoteIntel Ratings the Group has received and update the Group's Intel Rating.

Custom View Tab

The Custom View tab, available for Indicators and Groups only, allows you to display a customized view of the data that matter most to you when investigating these object types. See The Details Screen: Custom View for instructions on configuring the Indicator: Custom View and Group: Custom View tab on the Details screen for Indicators and Groups, respectively.

Overview Tab

The Overview tab of the new Details screen (Figure 1 and Figure 2) features several cards containing relevant information for the object you are viewing. Depending on the type of object you are viewing, the cards displayed on this tab will vary.

To collapse or expand all cards on the Overview tab, click the Collapse All or Expand All button, respectively, above the Details card. By default, all cards are expanded.

Intelligence Requirements

Table 1 provides a description of each card that may be displayed on the Overview tab of the new Details screen for an Intelligence Requirement (IR).

 

Card NameDescription
DetailsThe Details card is where you can view the IR’s creation and last modified dates, subtype, and category, as well as view and manage its default Description and Tags.

To edit the IR's subtype, category, or Description, click EditIcon  Description automatically generatedat the upper-right corner of the card; to edit the IR's Tags, click EditIcon  Description automatically generatedat the lower-right corner of the card. After making the desired changes, click the corresponding ConfirmConfirm icon_Details screenbutton to save those changes.
Keyword Tracking & ResultsThe Keyword Tracking & Results cardconsists of three sections:
  • Keyword Tracking: This section is where you can view and manage the keywords defined in the IR’s keyword query.
  • Results: This section is where you can view the local and global results returned by the IR’s keyword query and determine the appropriate course of action to take for each result: associate the result to the IR object, archive the result, or mark the result as a false result.
  • Archived Results: This section is where you can view the results that have been archived for the IR.
PlaybooksThe Playbooks card is where you can view and execute active Playbooks with a UserAction Trigger configured for IRs.

Indicators

Table 2 provides a description of each card that may be displayed on the Overview tab of the new Details screen for an Indicator and the Indicator types for which the card is available.

 

Card NameDescriptionApplicable Indicator Types
AttributesThe Attributes card is where you can view the Indicator’s Attributes, including those configured as default or pinned Attributes, create new Attributes, and manage existing Attributes.All
DetailsThe Details card is where you can view the Indicator’s ThreatAssess and CAL data (ThreatAssess score, CAL score, ThreatAssess and CAL impact factors, and CAL Classifiers) creation date, and last modified date, as well as view and manage its default Description, default Source, Security Labels, Tags, and Threat and Confidence Ratings.

To edit the Indicator’s Description, Source, Security Labels, Confidence Rating, or Threat Rating, click EditIcon  Description automatically generatedat the upper-right corner of the card; to edit the Indicator’s Tags, click EditIcon  Description automatically generatedat the lower-right corner of the card. After making the desired changes, click the corresponding ConfirmConfirm icon_Details screenbutton to save those changes.
Note
If a System Administrator has enabled private Indicators on your ThreatConnect instance, a Private checkbox will be displayed at the upper-right corner of the Details card. Select this checkbox to mark the Indicator as private.
Note
An Indicator’s default Description Attribute is not displayed on the Attributes card; it is displayed on the Details card only. If a second default Description Attribute is added to an Indicator, that Attribute will be displayed on the Details card and the former default Description Attribute will be displayed on the Attributes card.
All
DNS ResolutionFor Address Indicators, the DNS Resolution card displays Hosts that have resolved to the Address, presently or historically. For Host Indicators, this card displays Addresses that have resolved to the Host, presently or historically, and geographic information within ThreatConnect and CAL for those Addresses.

For both Indicator types, the DNS Resolutions card also displays location and count information for computers that attempted to access suspicious domains captured by Quad9® infrastructure within the last 90 days.
Address; Host
File Hash DetailsThe File Hash Details card is where you can view and edit the File Indicator’s MD5, SHA1, and SHA256 file hashes and file size. It also displays analytics about a file sample’s various hashes derived from CAL, if such data are available for the Indicator.
Note
If adding a new file hash to an existing File Indicator and a File Indicator containing that file hash exists in the same owner, you will be prompted to merge the two File Indicators into a single Indicator containing both file hashes and any Attributes, Security Labels, and Tags added to each Indicator.
File
GeoLocation DataThe GeoLocation Data card displays IP address geographic information within ThreatConnect and CAL for the Address Indicator.Address
Investigation LinksThe Investigation Links card provides links to search results of various third-party lookup and other information services. Each link is a shortcut to query results for the object, which will open in a new browser tab.All
Known File OccurrencesThe Known File Occurrences card is where you can create File Occurrences and view the filename, run path, and date of each File Occurrence added to the File Indicator.File
NotesThe Notes card is where you can view, create, and manage Notes (i.e., posts) for the Indicator.All
Observations, False Positives, & ImpressionsThe Observations, False Positives, & Impressions card is where you can view the number of observations and false positive reports for the Indicator in your ThreatConnect instance and report the Indicator as a false positive. This card also displays the number of observations, false positive reports, and impressions derived from CAL for the Indicator.All
Owners & FeedsThe Owners & Feeds card displays any additional owners to which the Indicator belongs, along with the Threat Rating and Confidence Rating assigned to it by those owners. It also displays any feeds that have reported the Indicator.All
Pinned Association AttributesThe Pinned Association Attributes card displays association Attributes added to Groups associated to the Indicator.All
PlaybooksThe Playbooks card is where you can view and execute active Playbooks with a UserAction Trigger configured for the Indicator’s type.All
WhoisThe Whois card displays WHOIS information for the Host Indicator.Host
Important
If CAL is turned off for your Organization or ThreatConnect instance, the following sections will not be displayed on the Overview tab of the Indicator’s Details screen:
  • The CAL™ Classifiers section of the Details card
  • The CAL™ Feeds section of the Owners & Feeds card
  • The CAL™ File Hash Information section of the File Hash Details card
  • The CAL™ Provider Information section of the Geolocation card
  • The Global CAL™ section of the Observations, False Positives, & Impressions card

Groups

Table 3 provides a description of each card that may be displayed on the Overview tab of the new Details screen for a Group and the Group types for which the card is available.

 

Card NameDescriptionApplicable Group Type(s)
AI InsightsThe AI Insights card, available only for Report Groups in the CAL Automated Threat Library (ATL) Source, displays an artificial intelligence–generated summary of the Group.
Note
AI insights are not available for Report Groups created in the CAL ATL Source on your ThreatConnect instance before the instance was upgraded to version 7.4.
Important
Artificial intelligence (AI) summarizers use algorithms and AI to condense text into shorter summaries, saving time and effort. However, summaries generated from non-English content may have lower accuracy than those generated from English content.
Report (in CAL ATL Source only)
AttributesThe Attributes card is where you can view the Group’s Attributes, including those configured as default or pinned Attributes, create new Attributes, and manage existing Attributes.All
DetailsThe Details card is where you can view the Group’s creation and last modified dates, as well as view and manage its default Description, default Source, Security Labels, and Tags.

To edit the Group’s Description, Source, or Security Labels, click EditIcon  Description automatically generatedat the upper-right corner of the card; to edit the Group’s Tags, click EditIcon  Description automatically generatedat the lower-right corner of the card. After making the desired changes, click the corresponding Confirmbutton to save those changes.
Note
A Group’s default Description Attribute is not displayed on the Attributes card; it is displayed on the Details card only. If a second default Description Attribute is added to a Group, that Description Attribute will be displayed on the Details card and the former default Description Attribute will be displayed on the Attributes card.
All
Document FileThe Document File card provides a thumbnail preview of the Group’s file and a link you can click to view the file in another browser tab. It also displays information about the file, such as the file name and type, and provides options for replacing and downloading the file.
Note
The Document File card displays thumbnail previews only for Excel®, HTML, PDF, PowerPoint®, and Word® files.
Important
If the Group’s file is stored in the Malware Vault, the Document File card will not display a thumbnail preview of the file or a link to view it. Also, if you replace a Group’s file that is stored in the Malware Vault, the new file will inherit the archive password from the previous file.
Document
NotesThe Notes card is where you can view, create, and manage Notes (i.e., posts) for the Group.All
Pinned Association AttributesThe Pinned Association Attributes card displays association Attributes added to Groups associated to the Group.All
PlaybooksThe Playbooks card is where you can view and execute active Playbooks with a UserAction Trigger configured for the Group’s type.All
Report FileThe Report File card provides a thumbnail preview of the Group’s file and a link you can click to view the file in another browser tab. It also displays information about the file, such as the file name and type, and provides options for replacing and downloading the file (if a file has been uploaded), as well as uploading a file (if a file was not uploaded during the Group’s creation).
Note
The Report File card displays thumbnail previews only for Excel, HTML, PDF, PowerPoint, and Word files.
Report

Associations Tab

The Associations tab (Figure 3) displays separate cards for Groups, Indicators, Victim Assets, Artifacts, and Cases associated to the object whose Details screen you are viewing (i.e., the primary object), with the total number of associated objects displayed to the right of the tab’s name. It also displays cards for potentially associated Cases and, for Groups only, Artifacts that you can review and consider adding as associations to the object. If viewing a Group’s Details screen, a card containing ThreatConnect Query Language (TQL) queries added to the Group for TQL associations will also be displayed.

Important
If cross-owner associations are not enabled on your ThreatConnect instance, the Artifacts, Cases, and Potential Associations cards will not be displayed for Indicators and Groups in Communities and Sources.

Figure 4_The Details Screen_7.0.0

 

Activity Tab

The Activity tab (Figure 4), available for Indicators and Groups only, displays an activity list for the object, including a summary of the activity performed and the date and time the activity occurred. If an activity was performed on an object before your ThreatConnect instance was upgraded to version 7.0.0 or newer, the text “Legacy Link: “ will be appended to its summary.

Note
Clicking a linked object in a non-legacy link will display the new Details screen for that object, whereas clicking a linked object in a legacy link will display the legacy Details screen for that object.

Graphical user interface, application, Teams  Description automatically generated

 

Enrichment Tab

For Indicators, the Enrichment tab (Figure 5) will be available if an enrichment service is available for its Indicator type. This tab displays a card for each available enrichment service (Farsight Security®, Shodan®, and VirusTotal™ in this example) that provides a summary of information retrieved from the enrichment service if it is enabled. Each card also includes a Retrieve Data button to retrieve new, instead of cached, data, and most cards include an Open Detailed View link to display a detailed view of the information retrieved from the enrichment service.

Graphical user interface, application, Teams  Description automatically generated

 

Legacy Details Screen View

The legacy Details screen view is available for all Indicator types, Group types, Tags, Tracks, and Victims. It is the only Details screen view available for Email, Signature, and Task Groups; Tags; Tracks; and Victims. For all other object types, the new Details screen view is the default view.

For more information on the legacy Details screen view, see The Details Screen (Legacy).


ThreatConnect® is a registered trademark, and CAL™ is a trademark, of ThreatConnect, Inc.
Farsight Security® is a registered trademark of DomainTools, LLC.
VirusTotal™ is a trademark of Google, Inc.

Excel®, PowerPoint®, and Word® are registered trademarks of Microsoft Corporation.
Quad9® is a registered trademark of Quad9 Foundation.
Shodan® is a registered trademark of Shodan.
MITRE ATT&CK® and ATT&CK® are registered trademarks of The MITRE Corporation.

20145-01 v.06.A


Was this article helpful?