---
title: "Viewing Search Results for All Object Types | ThreatConnect"
slug: "viewing-search-results-for-all-object-types"
description: "This article describes how to view, manage, sort, and filter search results on the Search: All Object Types screen in ThreatConnect."
tags: ["Viewing Data"]
updated: 2026-01-10T19:34:05Z
published: 2026-01-10T19:34:05Z
canonical: "knowledge.threatconnect.com/viewing-search-results-for-all-object-types"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://knowledge.threatconnect.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Viewing Search Results for All Object Types

## Overview

The ThreatConnect® search engine lets you search your entire dataset to quickly find data relevant to the item you are investigating. After you [run a search of all object types](https://knowledge.threatconnect.com/docs/searching-all-object-types) , the search engine returns a results set of [Indicators](https://knowledge.threatconnect.com/docs/en/the-threatconnect-data-model#indicators), [Groups](https://knowledge.threatconnect.com/docs/en/the-threatconnect-data-model#groups), [Tags](https://knowledge.threatconnect.com/docs/the-threatconnect-data-model#tags), [Victims](https://knowledge.threatconnect.com/docs/the-threatconnect-data-model#victims), and [Workflow Cases](https://knowledge.threatconnect.com/docs/the-threatconnect-data-model#workflow-cases) that match the search query, which you can then review and analyze as part of your investigation.

When looking for matches to a search query, the search engine searches an object’s summary and metadata—including [Attributes](https://knowledge.threatconnect.com/docs/attributes); [Descriptions](https://knowledge.threatconnect.com/docs/the-description-attribute); Case [Artifacts](https://knowledge.threatconnect.com/docs/the-threatconnect-data-model#artifacts), [Notes](https://knowledge.threatconnect.com/docs/case-notes), and [Tasks](https://knowledge.threatconnect.com/docs/phases-and-tasks); file and signature contents; Tags; and Victim Assets and Victim details—and provides a relevance-ordered result set based on how closely each result matches the query.

## Before You Start

### User Roles

- To view and export Indicators, Groups, Tags, or Victims in an Organization, your user account can have any [Organization role](https://knowledge.threatconnect.com/docs/organization-roles).
- To view and export Indicators, Groups, Tags, or Victims in a Community or Source, your user account must have a [Community role](https://knowledge.threatconnect.com/docs/community-roles) of User, Commenter, Contributor, Editor, or Director for that Community or Source.
- To view and export Cases in an Organization, your user account can have any Organization role except App Developer.
- To create copies of Indicators and add them to an Organization, your user account must have an Organization role of Standard User, Sharing User, Organization Administrator, or App Developer.
- To delete Indicators, Groups, standard Tags, or Victims in an Organization, your user account must have an Organization role of Standard User, Sharing User, Organization Administrator, or App Developer.
- To delete Indicators, Groups, standard Tags, or Victims in a Community or Source, your user account must have a Community role of Editor or Director for that Community or Source.
- To delete Cases in an Organization, your user account must have an Organization role of Organization Administrator.
- To apply Tags to Indicators, Groups, and Victims in an Organization, your user account must have an Organization role of Standard User, Sharing User, Organization Administrator, or App Developer.
- To apply Tags to Cases in an Organization, you must have an Organization role of Standard User, Sharing User, or Organization Administrator.
- To apply Tags to Indicators, Groups, and Victims in a Community or Source, your user account must have a Community role of Contributor, Editor, or Director for that Community or Source.

### Prerequisites

- To search your ThreatConnect data and view search results on the **Search: All Object Types**screen, turn on and configure OpenSearch® and initialize the search index for your ThreatConnect instance on the **System Settings**screen (must be a System Administrator to perform this action).
- To view and manage search results that are Cases, select the **Enable Workflow** checkbox on the **Permissions**tab of the **Organization Information** window when editing your Organization on the **Organizations**tab of the **Account Settings** screen (must be an Accounts Administrator, Operations Administrator, or System Administrator to perform this action).

## Viewing Search Results

After you [run a search of all object types](https://knowledge.threatconnect.com/docs/searching-all-object-types), the **Search: All Object Types**screen displays the search results in a paginated table with the following columns (Figure 1):

![Figure 1_Viewing Search Results_7.6.0](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Figure%201_Viewing%20Search%20Results%20for%20ALl%20Object%20Types_7.11.0.png)

- **Matched On**: The property of the result that matched the search query. To [view details about each property of a result that matched the search query](/docs/viewing-search-results-for-all-object-types#viewing-match-details-for-search-results), click the value or![Result Details icon](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Result%20Details%20icon.png)icon in the **Matched On**column. Table 1 defines the possible values for this column and the applicable result type for each value.
- **Type**: The result’s type. For Groups and Indicators, the **Type**column also displays the result's subtype (e.g., Address, Vulnerability).
- **Name/Summary**: The result’s name/summary.
- **Owner**: The result’s [owner](https://knowledge.threatconnect.com/docs/ownership-in-threatconnect).
- **Tags**: The [Tags](https://knowledge.threatconnect.com/docs/the-threatconnect-data-model#tags) applied to the result.
- **ThreatAssess**: (Indicators only) The result’s [ThreatAssess score](https://knowledge.threatconnect.com/docs/threatassess-and-cal).
- **Date Added**: The date and time the result was created in its owner.
- **Last Modified**: The date and time the result was [last modified](https://knowledge.threatconnect.com/docs/the-last-modified-date) in its owner.

HintYou can adjust the columns displayed in the table on the **Search: All Object Types**screen by clicking **Select columns![Select columns button](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Select%20columns%20button.png)**in the upper right, selecting the columns to display, and clicking **Apply**.

| “Matched On” Value | Description | Result Types |
| --- | --- | --- |
| Artifact | The summary of one or more of the result’s [Artifacts](https://knowledge.threatconnect.com/docs/the-threatconnect-data-model#artifacts) was a match. | Case |
| Attribute | The value of one or more of the result’s [Attributes](https://knowledge.threatconnect.com/docs/attributes) was a match. | Case, Indicator, Group, Tag, Victim |
| Case Description | The description of the result was a match. | Case |
| Description | The value of one or more of the result’s [Description Attributes](https://knowledge.threatconnect.com/docs/the-description-attribute) (default or non-default) was a match. | Indicator, Group, Tag, Victim |
| File Content | The contents of the file uploaded to the result were a match. | Group (Document and Report only) |
| Multiple Properties | Two or more of the result’s properties were a match. | Case, Indicator, Group, Tag, Victim |
| Name/Summary | The result’s name/summary was a match. | Case, Indicator, Group, Tag, Victim |
| Note | The contents of one or more of the result’s [Case Notes](https://knowledge.threatconnect.com/docs/case-notes) were a match. | Case |
| Signature | The contents of the signature file uploaded to the result were a match. | Group (Signature only) |
| Tag | The name of one or more [standard Tags](https://knowledge.threatconnect.com/docs/the-threatconnect-data-model#tags) or [ATT&CK® Tags](https://knowledge.threatconnect.com/docs/attack-tags) applied to the result was a match. | Case, Indicator, Group, Victim |
| Task | The name of one or more of the result’s [Tasks](https://knowledge.threatconnect.com/docs/phases-and-tasks) was a match. | Case |
| Task Description | The description of one or more of the result’s Tasks was a match. | Case |
| Victim Asset | The summary of one or more of the result’s Victim Assets was a match. | Victim |
| Victim Nationality | The result’s nationality was a match. | Victim |
| Victim Organization | The result’s organization was a match. | Victim |
| Victim Sub-Organization | The result’s sub-organization was a match. | Victim |
| Victim Work Location | The result’s work location was a match. | Victim |

### Viewing Match Details for Search Results

A search result’s **Result Details**drawer displays each of the result’s properties that matched the search query, with each part of the property that matched the query highlighted in blue. For example, in Figure 2, the following properties of the result matched the search query from Figure 1 (`ransomware 140.82.29.65 "scattered spider"`): the result’s name/summary, the value of the result’s Source Attribute, the value of the result’s Description Attribute, and the name of one of the result’s standard Tags.

![Figure 2_Viewing Search Results_7.7.0](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Figure%202_Viewing%20Search%20Results%20for%20All%20Object%20Types_7.9.0.png)

HintTo open the [**Details**screen](https://knowledge.threatconnect.com/docs/the-details-screen) from the **Result Details**drawer, click the object’s name at the upper left.

There are two ways to open a search result’s **Result Details**drawer on the **Search: All Object Types**screen:

- Click the value or![](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Result%20Details%20icon.png)icon in the result’s **Matched On**column.
- Click the result’s [**⋯**menu](/docs/viewing-search-results-for-all-object-types#search-result-options) and select **View Match Details**.

### Viewing Search Result Details

Click a search result’s table row, or click a result’s [**⋯**menu](/docs/viewing-search-results-for-all-object-types#search-result-options) and select **View Details**, to open the **Details**drawer for the corresponding [Case](https://knowledge.threatconnect.com/docs/the-details-drawer-for-workflow-cases), [Group, Indicator, Tag, or Victim](https://knowledge.threatconnect.com/docs/the-details-drawer) and view detailed information about the result.

To open a search result’s **[](https://knowledge.threatconnect.com/docs/the-details-screen)** [](https://knowledge.threatconnect.com/docs/the-details-screen)[**Details**screen](https://knowledge.threatconnect.com/docs/the-details-screen) [](https://knowledge.threatconnect.com/docs/the-details-screen)**[](https://knowledge.threatconnect.com/docs/the-details-screen)**, click the result’s name/summary in the results table on the **Search: All Object Types**screen.

HintSearch results will not persist if you navigate to a different screen in the browser tab. Click **View details in new tab![](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/View%20details%20in%20new%20tab%20icon.png)**next to a result’s name/summary to retain your search results when viewing a result’s **Details** screen.

## Managing Search Results

### Selection Actions

You can select one or more search results and then use **Selection Actions**dropdown to perform the following actions:

HintTo view only selected results in the results table, click the ***<#>* Selected** filter next to the **Selection Actions** dropdown.

- **Add Tags…**: Enter and apply Tags to all selected objects.NoteTags are applied only to objects in owners for which your user account has permission to create data. Tags are not applied to other Tags.
- **Export…**: Export all selected objects to a comma-separated values (CSV) file.NoteYou can export all objects in the results table, including those on other table pages, to a CSV file by clicking the **⋯** menu at the upper right of the **Search: All Object Types**screen and selecting **Export Returned Objects…**.
- **Add to Organization…**: Create copies of all selected Indicators and add them to your Organization.NoteIf no Indicators are selected, the **Add to Organization…**option will not be available. If both Indicators and other object types (e.g., Groups) are selected, only the Indicators will be added to your Organization.

### Search Result Options

You can use a search result’s **⋯** menu to manage and analyze the result. Table 2 describes the options available in the **⋯** menu and the applicable result types for each option.

| Search Result Option | Description | Result Types |
| --- | --- | --- |
| Add to Exclusion List | Add the result to your [Organization-level Exclusion List](https://knowledge.threatconnect.com/docs/creating-indicator-exclusion-lists). This option is available only if your user account has an Organization role of Organization Administrator and if the **excludeFromDetailsEnabled**system setting is turned on for your ThreatConnect instance.ImportantYou cannot [remove an Indicator from your Organization’s Exclusion List](https://knowledge.threatconnect.com/docs/creating-indicator-exclusion-lists#removing-an-indicator-from-an-exclusion-list) from the **Search: All Object Types** screen. | Indicator |
| Change Status to Active / Change Status to Inactive | Change the [Indicator Status](https://knowledge.threatconnect.com/docs/indicator-status) of the result. This option is available only if your user account has [permission to modify Indicator Status in the result's owner](https://knowledge.threatconnect.com/docs/indicator-status#user-roles). | Indicator |
| Create Custom Report | Create a [report](https://knowledge.threatconnect.com/docs/reports) for the result [from scratch](https://knowledge.threatconnect.com/docs/creating-a-report#creating-a-report-without-using-a-report-template) or [from a report template](https://knowledge.threatconnect.com/docs/creating-a-report#creating-a-report-from-a-report-template). This option is available only if your user account has permission to create reports. | Case, Group |
| Delete… | Delete the result from its owner. This option is available only if your user account has the requisite permissions in the result’s owner.NoteATT&CK Tags may not be deleted. | Case, Indicator, Group, Tag, Victim |
| Threat Graph | Open [Threat Graph](https://knowledge.threatconnect.com/docs/threat-graph)to visualize, explore, and analyze the result’s associations.Note<meta http-equiv="Content-Type" content="text/html;charset=UTF-8">The **Threat Graph** option is in the **Visual Analysis** dropdown for Group results. | Case, Indicator, Group, Tag |
| View Details | Open the result’s **[](https://knowledge.threatconnect.com/docs/the-details-drawer)** [](https://knowledge.threatconnect.com/docs/the-details-drawer)[**Details**drawer](https://knowledge.threatconnect.com/docs/the-details-drawer) [](https://knowledge.threatconnect.com/docs/the-details-drawer)**[](https://knowledge.threatconnect.com/docs/the-details-drawer)**. | Case, Indicator, Group, Tag, Victim |
| View Match Details | Open the **Result Details**drawer and [view details about the result’s properties that matched the search query](/docs/viewing-search-results-for-all-object-types#viewing-match-details-for-search-results). | Case, Indicator, Group, Tag, Victim |
| Visual Analysis | Dropdown with the **Threat Graph** and **Visualize ATT&CK** options. | Group |
| Visualize ATT&CK | Open the [ATT&CK Visualizer](https://knowledge.threatconnect.com/docs/attack-visualizer) and create a [standard ATT&CK view](https://knowledge.threatconnect.com/docs/standard-attack-views)with the Group added as an analysis layer.NoteThe Visualize **ATT&CK** option is in the **Visual Analysis** dropdown for Group results. | Group |

## Sorting Search Results

You can sort search results by any table column except **Matched On**. By default, search results are sorted by how closely they match the search query, where objects whose name/summary matches the query are listed at the top, followed by objects with metadata (e.g., an Attribute, a Tag) that matches the query.

NoteWhen sorting search results by the **Name/Summary**column, objects whose name/summary begins with a newline or whitespace character in the database will be sorted above all other results.

## Filtering Search Results

The **Search: All Object Types**screen provides the following options for filtering search results:

- The object type dropdown next to the **Exact Match**checkbox lets you filter results by the following ThreatConnect object types: Cases, Indicators, Groups, Tags, and Victims. Results are filtered automatically as you select options in the dropdown.
- The owner dropdown next to the **Filters![](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Filters%20button_Details%20screen.png)**menu lets you filter results by one or more owners. Results are filtered automatically as you select options in the dropdown.
- The **Filters![Filters button_Details screen](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Filters%20button_Details%20screen.png)**menu lets you filter results by object metadata. After selecting and configuring filters, click **Apply**. Results may be filtered by the following metadata:
  - Object Subtypes (Indicators and Groups only)
  - Date Added
  - Last Modified
  - Matched On (i.e., the property that matched the search query)
  - ThreatAssess (Indicators only)

NoteThe **Group Type**and **Indicator Type**filters in the **Filters![](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Filters%20button_Details%20screen.png)**menu apply only to results that are Groups and Indicators, respectively. If you configure the object type dropdown to exclude Groups or Indicators from the search results, the **Group Type**or **Indicator Type**filter, respectively, will be grayed out.

---

*ThreatConnect® is a registered trademark of ThreatConnect, Inc.* *OpenSearch® is a registered trademark of Amazon Web Services.* *MITRE ATT&CK® and ATT&CK® are registered trademarks of The MITRE Corporation.*

20075-06 v.04.A
