---
title: "The Details Screen | ThreatConnect"
slug: "the-details-screen"
description: "This article describes the Details screen in ThreatConnect. Topics covered include viewing an object's Details screen, elements on the Overview tab of the Details screen, and the tabs available on the Details screen for specific object types."
tags: ["Getting Started", "Viewing Data"]
updated: 2024-06-12T14:39:20Z
published: 2024-06-12T14:39:20Z
---

> ## Documentation Index
> Fetch the complete documentation index at: https://knowledge.threatconnect.com/llms.txt
> Use this file to discover all available pages before exploring further.

# The Details Screen

ImportantThis article covers the new **Details**screen introduced in ThreatConnect version 7.0. For more information on the legacy **Details**screen, which may include some functionality not yet available on the new **Details**screen, see [*The Details Screen (Legacy)*](https://knowledge.threatconnect.com/docs/the-details-screen-legacy).

## Overview

The **Details** screen is the main screen where you can view and manage information and metadata for the following ThreatConnect® object types: Intelligence Requirements, Indicators, Groups, Tags, Tracks, and Victims. Although data displayed on the **Details** screen depends on the type of object you are viewing, some of the most commonly displayed information includes Attributes added to the object, Security Labels and Tags applied to the object, a list of objects associated to the object you are viewing, and insights from [CAL](https://knowledge.threatconnect.com/docs/threatassess-and-cal)™. This screen also provides shortcuts to various ThreatConnect features, such as [reporting](https://knowledge.threatconnect.com/docs/reports), [Threat Graph](https://knowledge.threatconnect.com/docs/explore-in-graph), and the [ATT&CK® Visualizer](https://knowledge.threatconnect.com/docs/attack-visualizer).

## Before You Start

### User Roles

- To view the **Details**screen for a threat intelligence data object in an Organization, your user account can have any [Organization role](https://knowledge.threatconnect.com/docs/organization-roles).
- To view the **Details**screen for a threat intelligence data object in a Community or Source, your user account can have any [Community role](https://knowledge.threatconnect.com/docs/community-roles) except Banned for that Community or Source.
- To delete a threat intelligence data object in an Organization via the **Details**screen, your user account must have an Organization role of Standard User, Sharing User, Organization Administrator, or App Developer.
- To delete a threat intelligence data object in a Community or Source via the **Details**screen, your user account must have a Community role of Editor or Director for that Community or Source.

### Prerequisites

- To view information retrieved from CAL for Indicators, turn on CAL for your Organization and ThreatConnect instance (must be a System Administrator to perform this action).
- To display the **[](https://knowledge.threatconnect.com/docs/applying-tags#tags-across-owners-card)**[](https://knowledge.threatconnect.com/docs/applying-tags#tags-across-owners-card)[**Tags Across Owners**card](https://knowledge.threatconnect.com/docs/applying-tags#tags-across-owners-card)[](https://knowledge.threatconnect.com/docs/applying-tags#tags-across-owners-card)**[](https://knowledge.threatconnect.com/docs/applying-tags#tags-across-owners-card)** on the **Details**screen for Indicators, turn on the **multiSourceViewEnabled**system setting (must be a System Administrator to perform this action).

## Viewing the Details Screen

Follow these steps to view the **Details**screen for a threat intelligence data object:

1. Hover over **Browse** on the top navigation bar and select an object type (i.e., **Intelligence Requirements (IR)**, **Indicators**, **Groups**, **Tags**, **Tracks**, **Victims**, or **Victim Assets**) or subtype (e.g., **Host**, **Adversary**).
2. Hover over an object in the results table on the **[](https://knowledge.threatconnect.com/docs/the-browse-screen)**[](https://knowledge.threatconnect.com/docs/the-browse-screen)[**Browse**screen](https://knowledge.threatconnect.com/docs/the-browse-screen) and click one of the following icons in the **Summary**cell:
  - **View full details![View full details_Browse](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/View%20full%20details_Browse.png)**: Click this icon to open the object’s **Details**screen in the current browser tab.
  - **View full details in new tab**![View full details in new tab icon](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/View%20full%20details%20in%20new%20tab%20icon.png): Click this icon to open the object’s **Details**screen in a new browser tab.

Alternatively, select an object in the results table on the **Browse**screen to open its [**Details** drawer](https://knowledge.threatconnect.com/docs/the-details-drawer). Then click **View full details**![View full details_Details drawer](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/View%20full%20details_Details%20drawer.png)at the top right of the drawer (if viewing the **Details**drawer for a Group, Tag, Track, Victim, or Victim Asset) or the object’s summary at the top left of the drawer (if viewing the **Details**drawer for an Indicator) to open the object’s **Details**screen.

NoteThe **Details**drawer is not available for Intelligence Requirements at this time.NoteFor a Victim Asset, no icons are displayed when you hover over its entry in the table on the **Browse**screen. Instead, you must click on its entry in the results table to open its **Details**drawer. Then click **View full details**![Icon  Description automatically generated](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/View%20full%20details_Details%20drawer.png)at the top right of the****drawer to open the **Details**screen for the Victim to which the Victim Asset belongs.

## New Details Screen View

The new **Details**screen view is currently available for Intelligence Requirements, all Indicator types, and the following Group types: Adversary, Attack Pattern, Campaign, Course of Action, Document, Event, Incident, Intrusion Set, Malware, Report, Tactic, Threat, Tool, Vulnerability Groups. It is **not available** for Email, Signature, and Task Groups; Tags; Tracks; and Victims.

Figure 1 shows the **Overview**tab of the new **Details**screen for an Address Indicator (**71.6.135.131**), and Figure 2 shows the **Overview**tab of the new **Details**screen for an Adversary Group (**Bad Guy**).

NoteIf you are viewing an Indicator that does not exist in your Organization and your user account has an [Organization role](https://knowledge.threatconnect.com/docs/organization-roles) of Standard User, Sharing User, Organization Administrator, or App Developer, the Indicator’s **Details**screen will display a message stating the Indicator does not exist in your Organization and provide a link to create the Indicator in your Organization. If you click this link, the **Details**screen will show details for the copy of the Indicator in your Organization after it is created. In addition, if your System Administrator turned on the **multiSourceViewEnabled**system setting, your Organization will be listed on the [**Tags Across Owners**card](https://knowledge.threatconnect.com/docs/applying-tags#tags-across-owners-card) for the Indicator in addition to the Indicator’s other owners to which you have access.

![Figure 1_The Details Screen_7.1.0](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Figure%201_The%20Details%20Screen_7.6.0.png)

![Figure 2_The Details Screen_7.1.0](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Figure%202_The%20Details%20Screen_7.5.0.png)

### New Details Screen Header

#### Intelligence Requirements

For descriptions of each section and element included in the header of the **Details**screen for Intelligence Requirements, see the [“Details Screen Header” section of *Viewing Intelligence Requirement Details*](https://knowledge.threatconnect.com/docs/viewing-intelligence-requirement-details#details-screen-header).

#### Indicators

The new **Details**screen for Indicators (Figure 1) includes the following sections and elements in its header:

- **Browse /<*Object name>***: This section is located at the upper-left corner of the screen and includes a****link to view all Indicators on the **Browse**screen. It also displays the name of the Indicator whose **Details**screen you are viewing.
- **Object icon and name**: This section displays the Indicator’s name and an icon corresponding to its Indicator type.
- **<*Object type*> | <*Owner type: Owner name*>**: This section displays the Indicator’s type followed by the type and name of the owner to which it belongs. If the Indicator belongs to multiple owners, a dropdown from which you can select the owner in which you want to view the object’s **Details**screen will be displayed.
- **Revert to Legacy View**: Click **Revert to Legacy View**to open the [legacy **Details**screen](https://knowledge.threatconnect.com/docs/the-details-screen-legacy) for the Indicator.
- **Explore in Graph**: Click [**Explore In Graph**](https://knowledge.threatconnect.com/docs/explore-in-graph) to [view the Indicator in Threat Graph](https://knowledge.threatconnect.com/docs/accessing-an-objects-graph).
- **⋯ menu**: Click the **⋯**menu at the upper-right corner of the screen to display the following options:
  - **Pivot**: Select **Pivot** to [pivot](https://knowledge.threatconnect.com/docs/pivoting-on-data) to a list of all associated intelligence for the Indicator.
  - **Change Status to Active**: If viewing an Indicator whose status is inactive, select **Change Status to Active** to [set the Indicator’s status](https://knowledge.threatconnect.com/docs/indicator-status#viewing-and-setting-indicator-status-for-existing-indicators) to active.
  - **Change Status to Inactive**: If viewing an Indicator whose status is active, select **Change Status to Inactive**to set the Indicator’s status to inactive.
  - **Disable CAL Status Lock**: If [CAL Status Lock](https://knowledge.threatconnect.com/docs/indicator-status#viewing-and-setting-indicator-status-for-existing-indicators) is turned on for the Indicator, select **Disable CAL Status Lock**to turn off CAL Status Lock for the Indicator and allow CAL to change the Indicator’s status.
  - **Enable CAL Status Lock**: If CAL Status Lock is turned off for the Indicator, select **Enable CAL Status Lock**to turn on CAL Status Lock for the Indicator and prevent CAL from changing the Indicator’s status. Note that when CAL Status Lock is turned on for an Indicator, a message stating “CAL Status Lock Enabled” will be displayed in the header of the Indicator’s **Details**screen, below the **Follow Item**toggle.
  - **Add to Exclusion List**: Select **Add to Exclusion List**to [add the Indicator to the Indicator Exclusion List](https://knowledge.threatconnect.com/docs/creating-indicator-exclusion-lists#adding-an-indicator-to-an-exclusion-list-from-the-details-screen) corresponding to its Indicator type.
  - **Delete**: Select **Delete**to delete the Indicator.
- **Follow Item**: Turn on the **Follow Item**toggle to [receive alerts and updates](https://knowledge.threatconnect.com/docs/notifications-and-following#following-items) on changes to the object. Then use the **bell**![Icon  Description automatically generated](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Bell%20icon_Details%20screen.png)icons to set the desired notification priority, where **Low**is one![Icon  Description automatically generated](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Bell%20icon_Details%20screen.png)icon, **Medium**is two![Icon  Description automatically generated](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Bell%20icon_Details%20screen.png)icons, and **High**is three![Icon  Description automatically generated](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Bell%20icon_Details%20screen.png)icons.
- **Indicator Status**: This section displays the Indicator’s status and whether it was set locally (i.e., by a user with permission to change Indicator Status on your ThreatConnect instance) or by CAL. If an Indicator is added to an Exclusion List, the text “⊘ On Exclusion List” will be displayed to the right of the Indicator’s status.

ImportantThe **Add to Exclusion List**option will be available for Organization and System Administrators only on ThreatConnect instances where this functionality is turned on in the system settings. If you add an Indicator to an Exclusion List using this method, the only way to remove it from the Exclusion List is via the **Organization Config**screen, as detailed in the [“Adding an Indicator to an Exclusion List from the Details Screen” section of *Creating Indicator Exclusion Lists*](https://knowledge.threatconnect.com/docs/creating-indicator-exclusion-lists#adding-an-indicator-to-an-exclusion-list-from-the-details-screen).

#### Groups

The new **Details**screen for Groups (Figure 2) includes the following sections and elements in its header:

- **Browse /<*Object name*>**: This section is located at the top left of the screen and includes a****link to view all Groups on the **Browse**screen. It also includes the name of the Group whose **Details**screen you are viewing.
- **Object icon and name**: This section displays the Group’s name and an icon corresponding to its Group type. In addition, an **Edit![Icon Description automatically generated](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Edit%20button_Details%20card_Details%20screen.png)**button will be displayed to the right of the Group’s name that, when clicked, allows you to edit the name.
- **<*Object type*> | <*Owner type: Owner name*>**: This section displays the Group’s type followed by the type and name of the owner to which it belongs.
- **Revert to Legacy View**: Click **Revert to Legacy View** to open the [legacy **Details**screen](https://knowledge.threatconnect.com/docs/the-details-screen-legacy) for the Group.
- **+****Create Custom Report**: Click **+ Create Custom Report**to display the following options:
  - **Create New**: Select **Create New**to [create a report for the Group that is not based on a report template](https://knowledge.threatconnect.com/docs/creating-a-report#creating-a-group-report).
  - **Create From Group Template**…: Select **Create From Group Template…**to [create a report for the Group from a saved Group report template](https://knowledge.threatconnect.com/docs/creating-a-report#creating-a-report-from-a-group-report-template). Then select a saved Group report template to use.
- **Visual Analysis**: Click **Visual Analysis**to display the following options:
  - **Explore in Graph**: Select [**Explore In Graph**](https://knowledge.threatconnect.com/docs/explore-in-graph)****to [view the Group in Threat Graph](https://knowledge.threatconnect.com/docs/accessing-an-objects-graph).
  - **Visualize ATT&CK**: Select **[Visualize ATT&CK](https://knowledge.threatconnect.com/docs/attack-visualizer)**to [access the ATT&CK Visualizer](https://knowledge.threatconnect.com/docs/accessing-the-attack-visualizer#details-screen) and display a new standard ATT&CK view with the Group [added as an analysis layer](https://knowledge.threatconnect.com/docs/standard-attack-views#creating-standard-attck-views).
- **⋯ menu**: Click the **⋯**menu at the upper-right corner of the screen to display the following options:
  - **Pivot**: Select **Pivot**to [pivot](https://knowledge.threatconnect.com/docs/pivoting-on-data) to a list of all associated intelligence for the Group.
  - **Download PDF**: Select **Download PDF**to [generate a PDF document](https://knowledge.threatconnect.com/docs/generating-a-report-pdf-for-a-group) of the Group.
  - **Delete**: Select **Delete**to delete the Group.
- **Follow Item**: Turn on the **Follow Item**toggle to [receive alerts and updates](https://knowledge.threatconnect.com/docs/notifications-and-following#following-items) on changes to the object. Then use the **bell**![Icon  Description automatically generated](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Bell%20icon_Details%20screen.png)icons to set the desired notification priority, where **Low**is one![Icon  Description automatically generated](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Bell%20icon_Details%20screen.png)icon, **Medium**is two![Icon  Description automatically generated](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Bell%20icon_Details%20screen.png)icons, and **High**is three![Icon  Description automatically generated](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Bell%20icon_Details%20screen.png)icons.
- **Intel Rating**: This section is where you can view the number of **Upvote****![](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Thumbs%20Up%20icon_New.png)**and **Downvote**![](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Thumbs%20Down%20icon_New.png)Intel Ratings the Group has received and [update the Group's Intel Rating](https://knowledge.threatconnect.com/docs/group-intel-rating).

### Custom View Tab

The **Custom View**tab, available for Indicators and Groups only, allows you to display a customized view of the data that matter most to you when investigating these object types. See *[The Details Screen: Custom View](https://knowledge.threatconnect.com/docs/the-details-screen-custom-view)*for instructions on configuring the **Indicator: Custom View**and **Group: Custom View**tab on the **Details**screen for Indicators and Groups, respectively.

### Overview Tab

The **Overview**tab of the new **Details**screen (Figure 1 and Figure 2) features several cards containing relevant information for the object you are viewing. Depending on the type of object you are viewing, the cards displayed on this tab will vary.

To collapse or expand all cards on the **Overview**tab, click **Collapse All**or **Expand All**, respectively, above the **Details**card. By default, all cards are expanded.

#### Intelligence Requirements

Table 1 provides a description of each card that may be displayed on the **Overview**tab of the new **Details**screen for an Intelligence Requirement (IR).

| Card Name | Description |
| --- | --- |
| Details | The **Details**card is where you can view the IR’s creation and [last modified](https://knowledge.threatconnect.com/docs/the-last-modified-date) dates, as well as view and manage its subtype, [category](https://knowledge.threatconnect.com/docs/intelligence-requirement-categories), default [Description](https://knowledge.threatconnect.com/docs/the-description-attribute), and [Tags](https://knowledge.threatconnect.com/docs/applying-tags). |
| Keyword Tracking & Results | The [**Keyword Tracking & Results**card](https://knowledge.threatconnect.com/docs/viewing-intelligence-requirement-details#keyword-tracking-results)consists of three sections: - **[Keyword Tracking](https://knowledge.threatconnect.com/docs/viewing-intelligence-requirement-details#keyword-tracking)**: This****section is where you can view and manage the keywords defined in the IR’s keyword query. - **[Results](https://knowledge.threatconnect.com/docs/viewing-intelligence-requirement-details#results)**: This section is where you can view the local and global results returned by the IR’s keyword query and determine the appropriate course of action to take for each result: associate the result to the IR object, archive the result, or mark the result as a false result. - **[Archived Results](https://knowledge.threatconnect.com/docs/viewing-intelligence-requirement-details#archived-results)**: This section is where you can view the results that have been archived for the IR. |
| Playbooks | The **Playbooks**card is where you can view and execute active [Playbooks](https://knowledge.threatconnect.com/docs/playbooks) with a [UserAction Trigger](https://knowledge.threatconnect.com/docs/playbooks-the-useraction-trigger) configured for IRs. |

#### Indicators

Table 2 provides a description of each card that may be displayed on the **Overview**tab of the new **Details**screen for an Indicator and the Indicator types for which the card is available.

| Card Name | Description | Applicable Indicator Types |
| --- | --- | --- |
| Attributes | The **Attributes**card is where you can view the Indicator’s [Attributes](/docs/attributes), including those configured as default or pinned Attributes, create new Attributes, and manage existing Attributes. | All |
| Details | The **Details**card is where you can view the Indicator’s [ThreatAssess and CAL](https://knowledge.threatconnect.com/docs/threatassess-and-cal) data (ThreatAssess score, CAL score, ThreatAssess and CAL impact factors, and [CAL Classifiers](https://knowledge.threatconnect.com/docs/cal-classifiers-glossary)) creation date, and [last modified date](https://knowledge.threatconnect.com/docs/the-last-modified-date), as well as view and manage its default [Description](https://knowledge.threatconnect.com/docs/the-description-attribute), default [Source](https://knowledge.threatconnect.com/docs/sourcing-data), [Security Labels](https://knowledge.threatconnect.com/docs/applying-security-labels), [Tags](https://knowledge.threatconnect.com/docs/applying-tags), and [Threat and Confidence Ratings](https://knowledge.threatconnect.com/docs/setting-indicator-threat-and-confidence-ratings). ImportantIf your System Administrator turned on the **multiSourceViewEnabled**system setting, the Tags applied to the Indicator will be displayed on the **Tags Across Owners**card instead of the **Details**card, and they will be the Tags applied to the Indicator across all of the Indicator’s owners to which you have access.NoteIf your System Administrator turned on the system setting for private Indicators, the **Details**card will have a **Private**checkbox at the top right that you can use to mark the Indicator as [private](https://knowledge.threatconnect.com/docs/private-indicators).NoteAn Indicator’s default Description Attribute is not displayed on the **Attributes**card; it is displayed on the **Details**card only. If a second default Description Attribute is added to an Indicator, that Attribute will be displayed on the **Details**card and the former default Description Attribute will be displayed on the **Attributes**card. | All |
| DNS Resolution | For Address Indicators, the [**DNS Resolution**card](https://knowledge.threatconnect.com/docs/dns-resolutions) displays Hosts that have resolved to the Address, presently or historically. For Host Indicators, this card displays Addresses that have resolved to the Host, presently or historically, and geographic information within ThreatConnect and CAL for those Addresses. For both Indicator types, the **DNS Resolutions**card also displays location and count information for computers that attempted to access suspicious domains captured by Quad9® infrastructure within the last 90 days. | Address; Host |
| File Hash Details | The [**File Hash Details**card](/docs/managing-file-hashes-and-known-file-occurrences) is where you can view and edit the File Indicator’s MD5, SHA1, and SHA256 file hashes and file size. It also displays [analytics about a file sample’s various hashes derived from CAL](https://knowledge.threatconnect.com/docs/what-can-cal-do-for-you#file-hash-information), if such data are available for the Indicator.NoteIf adding a new file hash to an existing File Indicator and a File Indicator containing that file hash exists in the same owner, you will be prompted to merge the two File Indicators into a single Indicator containing both file hashes and any Attributes, Security Labels, and Tags added to each Indicator. | File |
| GeoLocation Data | The [**GeoLocation Data** card](/docs/ip-geolocation-data) displays IP address geographic information within ThreatConnect and CAL for the Address Indicator. | Address |
| Investigation Links | The **Investigation Links** card provides links to search results of various third-party lookup and other information services. Each link is a shortcut to query results for the object, which will open in a new browser tab. | All |
| Known File Occurrences | The [**Known File Occurrences**card](/docs/managing-file-hashes-and-known-file-occurrences) is where you can create File Occurrences and view the filename, run path, and date of each File Occurrence added to the File Indicator. | File |
| Notes | The **Notes**card is where you can view, create, and manage Notes (i.e., [posts](https://knowledge.threatconnect.com/docs/posts)) for the Indicator. | All |
| Observations, False Positives, & Impressions | The **Observations, False Positives, & Impressions** card is where you can view the number of observations and false positive reports for the Indicator in your ThreatConnect instance and****[report the Indicator as a false positive](https://knowledge.threatconnect.com/docs/viewing-and-reporting-false-positives). This card also displays the number of observations, false positive reports, and impressions derived from CAL for the Indicator. | All |
| Owners & Feeds | The **Owners & Feeds**card displays any additional [owners](https://knowledge.threatconnect.com/docs/ownership-in-threatconnect) to which the Indicator belongs, along with the Threat Rating and Confidence Rating assigned to it by those owners. It also displays any feeds that have reported the Indicator. | All |
| Pinned Association Attributes | The **Pinned Association Attributes**card displays [association Attributes](/docs/pinned-association-attributes) added to Groups associated to the Indicator. | All |
| Playbooks | The **Playbooks**card is where you can view and execute active [Playbooks](https://knowledge.threatconnect.com/docs/playbooks) with a [UserAction Trigger](https://knowledge.threatconnect.com/docs/playbooks-the-useraction-trigger) configured for the Indicator’s type. | All |
| Tags Across Owners | The **[](https://knowledge.threatconnect.com/docs/applying-tags#tags-across-owners-card)**[](https://knowledge.threatconnect.com/docs/applying-tags#tags-across-owners-card)[**Tags Across Owners**card](https://knowledge.threatconnect.com/docs/applying-tags#tags-across-owners-card)[](https://knowledge.threatconnect.com/docs/applying-tags#tags-across-owners-card)**[](https://knowledge.threatconnect.com/docs/applying-tags#tags-across-owners-card)** displays the Tags applied to the Indicator across all of the Indicator’s owners to which you have access. This card is available only if your System Administrator turned on the **multiSourceViewEnabled**system setting. Otherwise, the Tags applied to the Indicator will be displayed on the **Details**card, and they will be the Tags applied to the Indicator only in the owner listed at the top left of the **Details**screen. ImportantAs of ThreatConnect 7.6, the **Tags Across Owners**card is a beta feature. | All |
| Whois | The [**Whois**card](/docs/whois-registration-information) displays WHOIS information for the Host Indicator. | Host |

ImportantIf CAL is turned off for your Organization or ThreatConnect instance, the following sections will not be displayed on the **Overview**tab of the Indicator’s **Details**screen:

- The **CAL™ Classifiers**section of the **Details**card
- The **CAL™ Feeds**section of the **Owners & Feeds**card
- The **CAL™ File Hash Information**section of the **File Hash Details**card
- The **CAL™ Provider Information**section of the **GeoLocation Data**card
- The **Global CAL™**section of the **Observations, False Positives, & Impressions**card

#### Groups

Table 3 provides a description of each card that may be displayed on the **Overview**tab of the new **Details**screen for a Group and the Group types for which the card is available.

| Card Name | Description | Applicable Group Type(s) |
| --- | --- | --- |
| AI Insights | The **AI Insights**card, available only for Report Groups in the [CAL Automated Threat Library (ATL)](https://knowledge.threatconnect.com/docs/cal-automated-threat-library-atl)Source, displays an artificial intelligence–generated summary of the Group. NoteAI insights are not available for Report Groups created in the CAL ATL Source on your ThreatConnect instance before the instance was upgraded to version 7.4.ImportantArtificial intelligence (AI) summarizers use algorithms and AI to condense text into shorter summaries, saving time and effort. However, summaries generated from non-English content may have lower accuracy than those generated from English content. | Report (in CAL ATL Source only) |
| Attributes | The **Attributes**card is where you can view the Group’s [Attributes](/docs/attributes), including those configured as default or pinned Attributes, create new Attributes, and manage existing Attributes. | All |
| Details | The **Details**card is where you can view the Group’s creation and [last modified](https://knowledge.threatconnect.com/docs/the-last-modified-date) dates, as well as view and manage its default [Description](https://knowledge.threatconnect.com/docs/the-description-attribute), default [Source](/docs/sourcing-data), [Security Labels](https://knowledge.threatconnect.com/docs/applying-security-labels), and [Tags](https://knowledge.threatconnect.com/docs/applying-tags).NoteA Group’s default Description Attribute is not displayed on the **Attributes**card; it is displayed on the **Details**card only. If a second default Description Attribute is added to a Group, that Description Attribute will be displayed on the **Details**card and the former default Description Attribute will be displayed on the **Attributes**card. | All |
| Document File | The **Document File**card provides a thumbnail preview of the Group’s file and a link you can click to view the file in another browser tab. It also displays information about the file, such as the file name and type, and provides options for replacing and downloading the file.NoteThe **Document File**card displays thumbnail previews only for Excel®, HTML, PDF, PowerPoint®, and Word® files.ImportantIf the Group’s file is stored in the [Malware Vault](https://knowledge.threatconnect.com/docs/uploading-malware), the **Document File**card will not display a thumbnail preview of the file or a link to view it. Also, if you replace a Group’s file that is stored in the Malware Vault, the new file will inherit the archive password from the previous file. | Document |
| Notes | The **Notes**card is where you can view, create, and manage Notes (i.e., [posts](https://knowledge.threatconnect.com/docs/posts)) for the Group. | All |
| Pinned Association Attributes | The **Pinned Association Attributes**card displays [association Attributes](/docs/pinned-association-attributes) added to Groups associated to the Group. | All |
| Playbooks | The **Playbooks**card is where you can view and execute active [Playbooks](https://knowledge.threatconnect.com/docs/playbooks) with a [UserAction Trigger](https://knowledge.threatconnect.com/docs/playbooks-the-useraction-trigger) configured for the Group’s type. | All |
| Report File | The **Report File**card provides a thumbnail preview of the Group’s file and a link you can click to view the file in another browser tab. It also displays information about the file, such as the file name and type, and provides options for replacing and downloading the file (if a file has been uploaded), as well as uploading a file (if a file was not uploaded during the Group’s creation).NoteThe **Report File**card displays thumbnail previews only for Excel, HTML, PDF, PowerPoint, and Word files. | Report |

### Associations Tab

The [**Associations** tab](https://knowledge.threatconnect.com/docs/the-associations-tab) (Figure 3) displays separate cards for Groups, Indicators, Victim Assets, Artifacts, and Cases associated to the object whose **Details**screen you are viewing (i.e., the primary object), with the total number of associated objects displayed to the right of the tab’s name. It also displays cards for potentially associated Cases and, for Groups only, Artifacts that you can review and consider adding as associations to the object. If viewing a Group’s **Details**screen, a card containing [ThreatConnect Query Language (TQL) queries added to the Group](https://knowledge.threatconnect.com/docs/the-associations-tab#tql-queries) for TQL associations will also be displayed.

ImportantIf cross-owner associations are not enabled on your ThreatConnect instance, the **Artifact Associations**, **Case Associations**, and **Potential Associations** cards will not be displayed for Indicators and Groups in Communities and Sources.

![Figure 4_The Details Screen_7.0.0](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Figure%203_The%20Details%20Screen_7.6.0.png)

### Activity Tab

The **Activity** tab (Figure 4), available for Indicators and Groups only, displays an activity list for the object, including a summary of the activity performed and the date and time the activity occurred. If an activity was performed on an object before your ThreatConnect instance was upgraded to version 7.0.0 or newer, the text “Legacy Link: “ will be appended to its summary.

NoteClicking a linked object in a non-legacy link will display the new **Details**screen for that object, whereas clicking a linked object in a legacy link will display the legacy **Details**screen for that object.

![Graphical user interface, application, Teams Description automatically generated](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Figure%204_The%20Details%20Screen_7.6.0.png)

### Enrichment Tab

For Indicators, the [**Enrichment**tab](https://knowledge.threatconnect.com/docs/the-enrichment-tab) (Figure 5) will be available if an enrichment service is available for its Indicator type. This tab displays a card for each available enrichment service ([Farsight Security](https://knowledge.threatconnect.com/docs/farsight-security-passive-dns-enrichment)®, [Shodan](https://knowledge.threatconnect.com/docs/shodan-enrichment)®, and [VirusTotal](https://knowledge.threatconnect.com/docs/virustotal-enrichment)™ in this example) that provides a summary of information retrieved from the enrichment service if it is enabled. Each card also includes a **Retrieve Data**button to retrieve new, instead of cached, data, and most cards include an **Open Detailed View** link to display a detailed view of the information retrieved from the enrichment service.

![Graphical user interface, application, Teams Description automatically generated](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Figure%205_The%20Details%20Screen_7.6.0.png)

## Legacy Details Screen View

The legacy **Details**screen view is available for all Indicator types, Group types, Tags, Tracks, and Victims. It is the only **Details**screen view available for Email, Signature, and Task Groups; Tags; Tracks; and Victims. For all other object types, the new **Details** screen view is the default view.

For more information on the legacy **Details**screen view, see [*The Details Screen (Legacy)*](https://knowledge.threatconnect.com/docs/the-details-screen-legacy).

---

*ThreatConnect® is a registered trademark, and CAL™ is a trademark, of ThreatConnect, Inc.* *Farsight Security® is a registered trademark of DomainTools, LLC. VirusTotal™ is a trademark of Google, Inc.* *Excel®, PowerPoint®, and Word® are registered trademarks of Microsoft Corporation.* *Quad9® is a registered trademark of Quad9 Foundation.* *Shodan® is a registered trademark of Shodan.* *MITRE ATT&CK® and ATT&CK® are registered trademarks of The MITRE Corporation.*

20145-01 v.07.A

## Related

- [Applying Security Labels](/applying-security-labels.md)
- [Applying Tags](/applying-tags.md)
- [Attributes](/attributes.md)
- [Indicator Status](/indicator-status.md)
- [Notifications and Following](/notifications-and-following.md)
- [Pivoting on Data](/pivoting-on-data.md)
- [Setting Indicator Threat and Confidence Ratings](/setting-indicator-threat-and-confidence-ratings.md)
- [The Associations Tab](/the-associations-tab.md)
- [The Description Attribute](/the-description-attribute.md)
- [The Details Screen: Custom View](/the-details-screen-custom-view.md)
- [The Details Screen (Legacy)](/the-details-screen-legacy.md)
- [The Enrichment Tab](/the-enrichment-tab.md)
- [The Source Attribute](/the-source-attribute.md)
- [ThreatAssess and CAL](/threatassess-and-cal.md)
- [Viewing Intelligence Requirement Details](/viewing-intelligence-requirement-details.md)
