--- title: "Viewing Details in Threat Graph" slug: "viewing-details-in-threat-graph" description: "This article describes how to view details for Indicators, Groups, Cases, and Tags in Threat Graph." tags: ["Viewing Data", "Importing Data", "Connecting Data"] updated: 2024-09-18T15:34:12Z published: 2024-09-18T15:34:12Z canonical: "knowledge.threatconnect.com/viewing-details-in-threat-graph" --- > ## Documentation Index > Fetch the complete documentation index at: https://knowledge.threatconnect.com/llms.txt > Use this file to discover all available pages before exploring further. # Viewing Details in Threat Graph ## Overview The Threat Graph feature in ThreatConnect® provides a graph-based interface that you can use to discover, visualize, and contextualize associations and relationships between [Indicators](https://knowledge.threatconnect.com/docs/the-threatconnect-data-model#indicators), [Groups](https://knowledge.threatconnect.com/docs/the-threatconnect-data-model#groups), [Cases](https://knowledge.threatconnect.com/docs/workflow-cases), and [Tags](https://knowledge.threatconnect.com/docs/applying-tags). The **View Details** option in Threat Graph lets you view details for a node corresponding to an Indicator, Group, Tag, or Case that exists in ThreatConnect. You can also view details about Indicators, Groups, Tags, and Cases in the graph via the **Graph Objects** drawer. ## Before You Start ### User Roles - To view details about Indicators, Groups, and Tags in an Organization in Threat Graph, your user account can have any [Organization role](https://knowledge.threatconnect.com/docs/organization-roles). - To view details about Indicators, Groups, and Tags in a Community or Source in Threat Graph, your user account can have any [Community role](https://knowledge.threatconnect.com/docs/community-roles) except Banned for that Community or Source. - To view details about Cases in an Organization in Threat Graph, your user account can have any Organization role except App Developer. ### Prerequisites - To view details about Cases in Threat Graph, turn on Workflow for your Organization on the **Account Settings** screen (must be an Accounts Administrator, Operations Administrator, or System Administrator to perform this action). ## Viewing the Details Drawer For a Node Follow these steps to open the **Details** drawer for an Indicator, Group, Tag, or Case in Threat Graph: 1. [Open Threat Graph](https://knowledge.threatconnect.com/docs/viewing-an-object-in-threat-graph). 2. Select a node on the graph that corresponds to an Indicator, Group, Tag, or Case that exists in ThreatConnect. 3. Select **View Details** in the [node’s menu](https://knowledge.threatconnect.com/docs/viewing-an-object-in-threat-graph#threat-graph-node-menu-options) to open the Details drawer for the corresponding [Indicator, Group, Tag](https://knowledge.threatconnect.com/docs/the-details-drawer), or [Case](https://knowledge.threatconnect.com/docs/the-details-drawer-for-workflow-cases). If the selected object exists in multiple [owners](https://knowledge.threatconnect.com/docs/ownership-in-threatconnect), you will be prompted select the owner in which to view the object’s **Details** drawer in the **View Details** submenu. If you are viewing the **Details** drawer for an object that exists in multiple owners, the drawer’s header will include a dropdown that you can use to switch between the object’s **Details** drawer in each of its owners. ImportantIf there are multiple copies of a Group in a single owner (that is, there is more than one Group with the same name and type in an owner), you cannot choose which copy of the Group the **Details** drawer will open for in Threat Graph. Also, you cannot toggle between the **Details** drawer for each copy of the Group in a single owner.NoteIf you are viewing the **Details** drawer for an [ATT&CK® Tag](https://knowledge.threatconnect.com/docs/attack-tags), no owner will be listed in the drawer’s header. This is because ATT&CK Tags are system generated and do not belong to an owner. ## Viewing Details in the Graph Objects Drawer Follow these steps to open the **Graph Objects** drawer and view details for an Indicator, Group, Tag, or Case in Threat Graph: 1. [Open Threat Graph](https://knowledge.threatconnect.com/docs/viewing-an-object-in-threat-graph). 2. Click **View Table** in the Threat Graph header to open the **Graph Objects** drawer (Figure 1). The **Graph Objects** drawer displays all objects on the graph in a paginated table. NoteTo control which table columns are included in the table on the **Graph Objects** drawer, click **Select columns![Select columns button](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Select%20columns%20button.png)**to the right of the search bar.![Figure 1_Viewing Details in Threat Graph_7.7.0](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Figure%201_Viewing%20Details%20in%20Threat%20Graph_7.7.0.png) 3. (Optional) To open the **Details** drawer for an Indicator, Group, Tag, or Case that exists in ThreatConnect, click on the object’s row. NoteThe **Details** drawer is not available for objects that do not exist in ThreatConnect. 4. (Optional) To open the **Details** screen for an [Indicator, Group](https://knowledge.threatconnect.com/docs/the-details-screen), or [Tag](https://knowledge.threatconnect.com/docs/the-details-screen-legacy) that exists in ThreatConnect, click on the object’s name in the **Name** column. NoteYou cannot open a [Case’s **Details** screen](https://knowledge.threatconnect.com/docs/parts-of-a-case) from the **Graph Objects** drawer. Instead, you must open the Case’s **Details** drawer and then click **View case in new tab![Open in New Tab icon](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Open%20in%20New%20Tab%20icon.png)**in the drawer’s header to open the Case’s **Details** screen. --- *ThreatConnect® is a registered trademark, and CAL™ is a trademark, of ThreatConnect, Inc.* *MITRE ATT&CK® and ATT&CK® are registered trademarks of The MITRE Corporation.* 20117-06 v.08.A