# ThreatConnect Knowledge Base > Knowledge base documentation for ThreatConnect Knowledge Base. ## v1 - [Getting Started With the ThreatConnect Knowledge Base](https://knowledge.threatconnect.com/docs/getting-started-with-the-threatconnect-knowledge-base.md): This article highlights key features in the ThreatConnect Knowledge Base and provides helpful tips for finding and viewing Knowledge Base articles. - [CAL 3.15.4 Release Notes](https://knowledge.threatconnect.com/docs/cal-3-15-4-release-notes.md): This article provides the CAL 3.15.4 release notes. - [CAL 3.15 Release Notes](https://knowledge.threatconnect.com/docs/cal-3-15-release-notes.md): This article provides the CAL 3.15 release notes. - [CAL 3.14 Release Notes](https://knowledge.threatconnect.com/docs/cal-3-14-release-notes.md): This article provides the CAL 3.14 release notes. - [CAL 3.13 Release Notes](https://knowledge.threatconnect.com/docs/cal-3-13-release-notes.md): This article provides the CAL 3.13 release notes. - [CAL 3.12 Release Notes](https://knowledge.threatconnect.com/docs/cal-3-12-release-notes.md): This article provides the CAL 3.12 release notes. - [CAL 3.11 Release Notes](https://knowledge.threatconnect.com/docs/cal-3-11-release-notes.md): This article provides the CAL 3.11 release notes. - [CAL 3.10 Release Notes](https://knowledge.threatconnect.com/docs/cal-3-10-release-notes.md): This article provides the CAL 3.10 release notes. - [CAL 3.9 Release Notes](https://knowledge.threatconnect.com/docs/cal-3-9-release-notes.md): This article provides the CAL 3.9 release notes. - [CAL 3.8 Release Notes](https://knowledge.threatconnect.com/docs/cal-3-8-release-notes.md): This article provides the CAL 3.8 release notes. - [CAL 3.7 Release Notes](https://knowledge.threatconnect.com/docs/cal-3-7-release-notes.md): This article provides the CAL 3.7 release notes. - [Polarity Desktop Client v5](https://knowledge.threatconnect.com/docs/polarity-desktop-client-v5.md) - [Polarity Server v5 (Platform)](https://knowledge.threatconnect.com/docs/polarity-server-v5-platform.md): Discover new features, improvements, and updates in Polarity Server v5. Learn what's included in the latest enterprise annotation platform release. - [Polarity Web V5 (UI)](https://knowledge.threatconnect.com/docs/polarity-web-v5-ui.md): Discover what's new in Polarity Web V5. Learn about UI improvements, features, and enhancements in the latest release. - [RQ 7.8 and 7.9 Release Notes](https://knowledge.threatconnect.com/docs/rq-78-and-79-release-notes.md): This article provides a PDF file of the ThreatConnect Risk Quantifier (RQ) 7.7 release notes. - [RQ 7.7 Release Notes](https://knowledge.threatconnect.com/docs/rq-77-release-notes.md): This article provides a PDF file of the ThreatConnect Risk Quantifier (RQ) 7.7 release notes. - [RQ 7.6 Release Notes](https://knowledge.threatconnect.com/docs/rq-76-release-notes.md): This article provides a PDF file of the ThreatConnect Risk Quantifier (RQ) 7.6 release notes. - [RQ 7.0 Release Notes](https://knowledge.threatconnect.com/docs/rq-70-release-notes.md): This article provides a PDF file of the ThreatConnect Risk Quantifier (RQ) 7.0 release notes. - [8.0 Release Notes](https://knowledge.threatconnect.com/docs/8-0-release-notes.md): This article provides the ThreatConnect 8.0 release notes. - [7.12 Release Notes](https://knowledge.threatconnect.com/docs/7-12-release-notes.md): This article provides the ThreatConnect 7.12 release notes. - [7.11 Release Notes](https://knowledge.threatconnect.com/docs/7-11-release-notes.md): This article provides the ThreatConnect 7.11 release notes. - [7.10 Release Notes](https://knowledge.threatconnect.com/docs/7-10-release-notes.md): This article provides the ThreatConnect 7.10 release notes. - [7.9 Release Notes](https://knowledge.threatconnect.com/docs/7-9-release-notes.md): This article provides the ThreatConnect 7.9 release notes. - [7.8 Release Notes](https://knowledge.threatconnect.com/docs/7-8-release-notes.md): This article provides the ThreatConnect 7.8 release notes. - [7.7 Release Notes](https://knowledge.threatconnect.com/docs/7-7-release-notes.md): This article provides a PDF file of the ThreatConnect 7.6 release notes. - [7.6 Release Notes](https://knowledge.threatconnect.com/docs/7-6-release-notes.md): This article provides a PDF file of the ThreatConnect 7.6 release notes. - [7.5 Release Notes](https://knowledge.threatconnect.com/docs/7-5-release-notes.md): This article provides a PDF file of the ThreatConnect 7.5 release notes. - [7.4 Release Notes](https://knowledge.threatconnect.com/docs/7-4-release-notes.md): This article provides a PDF file of the ThreatConnect 7.4 release notes. - [7.3 Release Notes](https://knowledge.threatconnect.com/docs/7-3-release-notes.md): This article provides a PDF file of the ThreatConnect 7.3 release notes. - [7.2 Release Notes](https://knowledge.threatconnect.com/docs/7-2-release-notes.md): This article provides a PDF file of the ThreatConnect 7.2 release notes. - [7.1 Release Notes](https://knowledge.threatconnect.com/docs/7-1-release-notes.md): This article provides a PDF file of the ThreatConnect 7.1 release notes. - [7.0 Release Notes](https://knowledge.threatconnect.com/docs/7-0-release-notes.md): This article provides a PDF file of the ThreatConnect 7.0 release notes. - [6.7 Release Notes](https://knowledge.threatconnect.com/docs/6-7-release-notes.md): This article provides a PDF file of the ThreatConnect 6.7 release notes. - [The ThreatConnect Data Model](https://knowledge.threatconnect.com/docs/the-threatconnect-data-model.md): This article introduces the basic data objects in ThreatConnect: Indicators and Groups. It describes all of the Indicator and Group types, demonstrates how to view Indicators and Groups, and provides basic information about associations. - [ThreatConnect Glossary](https://knowledge.threatconnect.com/docs/threatconnect-glossary.md): This article provides definitions of important and commonly used terms in ThreatConnect. - [ThreatConnect Owner Roles and Permissions Overview](https://knowledge.threatconnect.com/docs/threatconnect-owner-roles-and-permissions-overview.md): This article provides an overview of owner roles and permissions in ThreatConnect and the corresponding minimum roles and prerequisites for this feature. - [Viewing Owner Roles](https://knowledge.threatconnect.com/docs/viewing-owner-roles.md): This article describes how to view out-of-the-box and custom owner roles on the Owner Roles tab of the Account Settings screen in ThreatConnect. - [Organization Roles](https://knowledge.threatconnect.com/docs/organization-roles.md): This article defines all Organization roles in ThreatConnect and lists all permissions for each Organization role with respect to Organization administration, threat intelligence, Workflow, and Playbooks. - [Community Roles](https://knowledge.threatconnect.com/docs/community-roles.md): This article defines all Community roles in ThreatConnect and lists all permissions for each Community role with respect to Community administration and threat intelligence. - [Creating Custom Owner Roles](https://knowledge.threatconnect.com/docs/creating-custom-owner-roles.md): This article describes how to create custom owner roles in ThreatConnect. - [Owner Role Permissions Definitions](https://knowledge.threatconnect.com/docs/owner-role-permissions-definitions.md): This article defines all of the permissions settings for all Organization and Community roles in ThreatConnect. - [ThreatConnect Super User Overview](https://knowledge.threatconnect.com/docs/threatconnect-super-user-overview.md): This article provides an overview of a Super User account in ThreatConnect and the areas of ThreatConnect in which Super Users can manage data in all Organizations on their instance. - [Managing Data in All Organizations: Dashboard](https://knowledge.threatconnect.com/docs/managing-data-in-all-organizations-dashboard.md): This article describes how Super Users can determine which Organizations' data to display on the Dashboard screen and configure dashboard cards to show data from selected Organizations. - [Managing Data in All Organizations: Posts](https://knowledge.threatconnect.com/docs/managing-data-in-all-organizations-posts.md): This article describes how Super Users can view and manage data on the Posts screen in all Organizations on their ThreatConnect instance. - [Managing Data in All Organizations: Threat Intelligence](https://knowledge.threatconnect.com/docs/managing-data-in-all-organizations-threat-intelligence.md): This article describes how Super Users can view, create, import, filter, search for, modify, and delete threat intelligence in all Organizations on their ThreatConnect instance. - [Managing Data in All Organizations: Workflow](https://knowledge.threatconnect.com/docs/managing-data-in-all-organizations-workflow.md): This article describes how Super Users can can view, create, modify, assign, and delete Workflow Tasks, Workflows, Templates, and Cases in all Organizations on their ThreatConnect instance. - [Managing Data in All Organizations: Playbooks](https://knowledge.threatconnect.com/docs/managing-data-in-all-organizations-playbooks.md): This article describes how Super Users can view, manage, create, and import Playbooks in all Organizations on their ThreatConnect instance. - [Managing Data in All Organizations: Reports and Report Templates](https://knowledge.threatconnect.com/docs/managing-data-in-all-organizations-reports-and-report-templates.md): This article describes how Super Users can view and manage reports and templates in their home Organizations on their ThreatConnect instance. - [Administration and Configuration of All Organizations](https://knowledge.threatconnect.com/docs/administration-and-configuration-of-all-organizations.md): This article describes how Super Users can view, modify, and manage the Organization Settings and Organization Config screens for all Organizations on their ThreatConnect instance. - [ThreatConnect System Roles and Permissions](https://knowledge.threatconnect.com/docs/threatconnect-system-roles-and-permissions.md): Your System role determines your System-level permissions on your ThreatConnect instance. This article defines all ThreatConnect System roles, including the access and permissions each role has on each tab of the Settings menu screens. - [Ownership in ThreatConnect](https://knowledge.threatconnect.com/docs/ownership-in-threatconnect.md): Each threat intelligence data object in ThreatConnect has an owner. This article discusses the different types of owners (Organization, Community, and Source) and describes how Indicators that have multiple owners are maintained as separate copies. - [ThreatConnect Versioning](https://knowledge.threatconnect.com/docs/threatconnect-versioning.md): This article describes the version numbering scheme used for each ThreatConnect release and provides instructions for how to determine the version and build of ThreatConnect running on your instance and the associated commit. - [The Diamond Model](https://knowledge.threatconnect.com/docs/the-diamond-model.md): This article explains the Diamond Model of Intrusion Analysis, on which the ThreatConnect object model is based, and the concepts of associations and pivots, which are ways to express the navigations of the Diamond Model. - [My Intel Sources](https://knowledge.threatconnect.com/docs/my-intel-sources.md): This article describes how to use the My Intel Sources selector in ThreatConnect. - [Viewing Owner ID Numbers](https://knowledge.threatconnect.com/docs/viewing-owner-id-numbers.md): This article describes the various screens where you can view an owner’s ID number in ThreatConnect. - [Assigning Tasks](https://knowledge.threatconnect.com/docs/assigning-tasks.md): This article describes how to create Task Groups in ThreatConnect, including setting up reminders, due dates, and escalation details. It also demonstrates how to reassign a Task Group to a different ThreatConnect user. - [Creating Indicators](https://knowledge.threatconnect.com/docs/creating-indicators.md): This article describes how to create Indicators using the + Create & Import option on the Search: Indicators screen in ThreatConnect. - [Creating Groups](https://knowledge.threatconnect.com/docs/creating-groups.md): This article describes how to create Groups using the + Create & Import option on the Search: Groups screen in ThreatConnect. - [Creating Victims](https://knowledge.threatconnect.com/docs/creating-victims.md): This article describes how to create Victims using the + Create Victim option on the Search: Victims screen in ThreatConnect. - [Creating Intelligence Requirements](https://knowledge.threatconnect.com/docs/creating-intelligence-requirements-1.md): This article describes how to create Intelligence Requirements in ThreatConnect. - [Document Parsing Import](https://knowledge.threatconnect.com/docs/document-parsing-import.md): This article describes how to use the Document Parsing Import feature in ThreatConnect to import Groups and Indicators from an unstructured file or a text block. - [Email Import](https://knowledge.threatconnect.com/docs/email-import.md): This article discusses how to import an email (e.g., a malicious or suspicious email) into ThreatConnect as an Email Group and select Indicators from the email to associate to the Email Group and, optionally, to Victims. - [Signature Import](https://knowledge.threatconnect.com/docs/signature-import.md): This article demonstrates how to import a Signature Group into ThreatConnect. - [Structured Indicator Import](https://knowledge.threatconnect.com/docs/structured-indicator-import.md): This article describes how to extract Indicators from structured comma-separated values (CSV) files and import them into ThreatConnect. - [Unstructured Indicator Import](https://knowledge.threatconnect.com/docs/unstructured-indicator-import.md): This article discusses how to import Indicators from unstructured documents into ThreatConnect. - [Uploading Malware](https://knowledge.threatconnect.com/docs/uploading-malware.md): This article describes how to upload a file to the Malware Vault in ThreatConnect and create a Document Group for the file. It also demonstrates how Organization Administrators can restrict uploads to the Malware Vault for Communities. - [Using Automated Email Ingest](https://knowledge.threatconnect.com/docs/using-automated-email-ingest.md): This article describes how to set up Phishing and Feed mailboxes for automated ingestion of Indicators and phishing emails into ThreatConnect. - [Adding Adversary Assets](https://knowledge.threatconnect.com/docs/adding-adversary-assets.md): This article describes how to add an Adversary Asset to an Adversary Group in ThreatConnect. - [Applying Security Labels](https://knowledge.threatconnect.com/docs/applying-security-labels.md): This article describes how to apply Security Labels to Indicators, Groups, and Victims in ThreatConnect. - [Applying Tags](https://knowledge.threatconnect.com/docs/applying-tags.md): This article provides best practices for naming and administrating Tags in ThreatConnect. It also describes how to view a Tag’s details and manage Tags for Indicators, Groups, and Victims. - [ATT&CK Tags](https://knowledge.threatconnect.com/docs/attck-tags.md): This article describes ATT&CK Tags in ThreatConnect, including how to view them, identify objects to which they are applied, and apply them to objects. It also describes ATT&CK Tag conversion rules and how to configure them. - [Attributes](https://knowledge.threatconnect.com/docs/attributes.md): This article describes how to create and manage Attributes, explains the function of default and pinned Attributes, and describes how to enable and use Markdown in an Attribute. - [Group Intel Rating](https://knowledge.threatconnect.com/docs/group-intel-rating.md): This article describes how to update a Group’s Intel Rating in ThreatConnect and view Intel Rating counts for Groups on the Browse screen. - [Intelligence Reviews](https://knowledge.threatconnect.com/docs/intelligence-reviews.md): Learn how Polarity General lets you add metadata and reviews to ThreatConnect threat intelligence objects. Enrich threat data with annotations, tags, and collaborative notes to improve threat assessment and team awareness. - [Managing File Hashes and Known File Occurrences](https://knowledge.threatconnect.com/docs/managing-file-hashes-and-known-file-occurrences.md): This article describes how to manage a File Indicator’s hashes, size, and File Occurrences. It also describes how to merge two File Indicators with different hash types into a single File Indicator containing both hashes. - [Pinned Association Attributes](https://knowledge.threatconnect.com/docs/pinned-association-attributes.md): This article describes the Pinned Association Attributes card on the Details screen. This card displays association Attributes that belong to Groups associated to the object whose Details screen you are viewing. - [The Description Attribute](https://knowledge.threatconnect.com/docs/the-description-attribute.md): This article describes how to view, create, and manage Description Attributes for Indicators, Groups, and Victims, as well as Descriptions for Tags and Tracks . - [The Source Attribute](https://knowledge.threatconnect.com/docs/the-source-attribute.md): This article discusses how to use and administrate the Source Attribute in ThreatConnect. - [Best Practices: Indicator Threat and Confidence Ratings](https://knowledge.threatconnect.com/docs/best-practices-indicator-threat-and-confidence-ratings.md): This article outlines best practices to follow when setting an Indicator’s Threat and Confidence Ratings in ThreatConnect. - [Setting Indicator Threat and Confidence Ratings](https://knowledge.threatconnect.com/docs/setting-indicator-threat-and-confidence-ratings.md): This article defines Threat Rating and Confidence Rating for Indicators in ThreatConnect and demonstrates how to set these values for an Indicator. - [AI Exploited-Vulnerability Analyzer](https://knowledge.threatconnect.com/docs/ai-exploited-vulnerability-analyzer.md): This article describes how the AI Exploited-Vulnerability Analyzer uses Tags and focused AI summaries to enrich Reports on zero-day and exploited vulnerabilities in the CAL Automated Threat Library Source. - [Automated Detection-Signature Extraction](https://knowledge.threatconnect.com/docs/automated-detection-signature-extraction.md): This article describes CAL Doc Analysis Service’s Automated Detection Signature Extraction. It lists the rule types and metadata the feature processes and explains how CAL ATL extracts detection signatures as Signature Groups in ThreatConnect. - [CAL Automated Threat Library (ATL)](https://knowledge.threatconnect.com/docs/cal-automated-threat-library-atl.md): This article describes the CAL Automated Threat Library (ATL) in ThreatConnect, a data source that is an evolution of the Technical Blogs and Reports (TBR) Source. - [CAL Automated Threat Library (ATL) Supported Blogs](https://knowledge.threatconnect.com/docs/cal-automated-threat-library-atl-supported-blogs.md): This article lists the blogs from which ThreatConnect’s CAL Automated Threat Library (ATL) sources its data. It also provides the source URL and corresponding ThreatConnect Tag for each blog. - [Prepare for CAL ATL Changes in CAL 3.15 Release](https://knowledge.threatconnect.com/docs/prepare-for-cal-atl-changes-in-cal-3-15-release.md): This document outlines the changes to CAL ATL included in the CAL 3.15 release, scheduled for late March 2026. It provides details about the sub-sources of CAL ATL that will be changing and how to update potentially impacted workflows. - [CAL Classifiers](https://knowledge.threatconnect.com/docs/cal-classifiers.md): This article explains what CAL Classifiers are, describes how to view an Indicator’s CAL Classifiers in ThreatConnect and Polarity, and defines all available CAL Classifiers. - [CAL Doc Analysis Service](https://knowledge.threatconnect.com/docs/cal-doc-analysis-service.md): This article describes the features of the CAL Doc Analysis Service, where they exist in the ThreatConnect platform, and how they handle data. - [CAL Global Threat Score](https://knowledge.threatconnect.com/docs/cal-global-threat-score.md): This article describes the CAL Global Threat Score to help customers using ThreatConnect, Polarity, and Dataminr Pulse understand how the CAL Global Threat Score works and how to interpret it within cyber threat intelligence workflows. - [CAL Indicator Enrichments](https://knowledge.threatconnect.com/docs/cal-indicator-enrichments.md): This article describes how CAL enriches Indicators with global intelligence, metadata, and analytics derived from data sources such as customer-available feeds, enrichment-only feeds, data-driven classifiers, and known-good intelligence. - [CAL Safelist and Known Good Indicators](https://knowledge.threatconnect.com/docs/cal-safelist-and-known-good-indicators.md): This article describes the CAL Safelist & “known good” label for Indicators in ThreatConnect & Polarity. It discusses how to identify CAL Safelist & “known good” Indicators & how being on the CAL Safelist affects Indicators in TC & Polarity. - [NAICS AI Industry Classification](https://knowledge.threatconnect.com/docs/naics-ai-industry-classification.md): This article describes NAICS AI industry classification, which applies Tags representing NAICS sectors to CAL ATL Reports and objects imported by the ThreatConnect Doc Analysis Playbook App and provides NAICS-specific IR keyword suggestions. - [ThreatAssess and CAL](https://knowledge.threatconnect.com/docs/threatassess-and-cal.md): This article provides an overview of ThreatAssess and CAL metrics for Indicators and how to view these metrics in ThreatConnect. - [What Can CAL Do For You?](https://knowledge.threatconnect.com/docs/what-can-cal-do-for-you.md): This article describes reputation, Classifiers, and contextual fields in ThreatConnect CAL and provides simple, intermediate, and advanced use cases for each. - [Exporting Groups](https://knowledge.threatconnect.com/docs/exporting-groups.md): This article describes how to export a set of Groups from the Browse screen into a CSV file. - [Exporting Indicators](https://knowledge.threatconnect.com/docs/exporting-indicators.md): This article describes how to export a set of Indicators from the Browse screen into a CSV file. It also shows how to export a set of Indicators associated to a Group or to another Indicator from that object’s legacy Details screen into a CSV file. - [The Browse Screen](https://knowledge.threatconnect.com/docs/the-browse-screen.md): This article describes all of the elements on the Browse screen in ThreatConnect and provides instruction on viewing, searching, filtering, exporting, and deleting threat intelligence data on this screen. - [The Details Drawer](https://knowledge.threatconnect.com/docs/the-details-drawer.md): This article describes the Details drawer for threat intelligence data and provides information on the actions you can perform from this drawer. - [The Details Screen](https://knowledge.threatconnect.com/docs/the-details-screen.md): This article describes the Details screen in ThreatConnect. Topics covered include viewing an object's Details screen, elements on the Overview tab of the Details screen, and the tabs available on the Details screen for specific object types. - [The Details Screen: Custom View](https://knowledge.threatconnect.com/docs/the-details-screen-custom-view.md): This article describes how to access and manage the Custom View tab on the Details screen for Groups and Indicators. - [The Details Screen (Legacy)](https://knowledge.threatconnect.com/docs/the-details-screen-legacy.md): This article describes the legacy Details screen in ThreatConnect. Topics covered include viewing an object's legacy Details screen, elements on the Overview tab, and the tabs available on the legacy Details screen for specific object types. - [Associations Overview](https://knowledge.threatconnect.com/docs/associations-overview.md): This article describes associations in ThreatConnect and the corresponding minimum roles and prerequisites for this feature. - [Graph View Overview](https://knowledge.threatconnect.com/docs/graph-view-overview.md): This article describes the basics of viewing the Associations card on the Overview tab of the Details screen in graph view. - [Graph View: Object Menu](https://knowledge.threatconnect.com/docs/graph-view-object-menu.md): This article describes the menu displayed when you click on an a node representing an associated object while viewing the Associations card on of the Overview tab of the Details screen in graph view. - [Graph View: Settings](https://knowledge.threatconnect.com/docs/graph-view-settings.md): This article describes the settings available when viewing the Associations card on the Overview tab of the Details screen in graph view. - [Table View Overview](https://knowledge.threatconnect.com/docs/table-view-overview.md): This article provides an overview of the table view available for the Associations card on the Overview tab of the Details screen. - [Table View: Associated Groups](https://knowledge.threatconnect.com/docs/table-view-associated-groups.md): This article describes the Associated Groups section of the Associations card on the Overview tab of the Details screen, which is displayed when viewing the Associations card in table view. - [Table View: Associated Indicators](https://knowledge.threatconnect.com/docs/table-view-associated-indicators.md): This article describes the Associated Indicators section of the Associations card on the Overview tab of the Details screen, which is displayed when viewing the Associations card in table view. - [Table View: Associated Victim Assets](https://knowledge.threatconnect.com/docs/table-view-associated-victim-assets.md): This article describes the Associated Victim Assets section of the Associations card on the Overview tab of the Details screen, which is displayed when viewing the Associations card in table view. - [Table View: Associated Artifacts](https://knowledge.threatconnect.com/docs/table-view-associated-artifacts.md): This article describes the Associated Artifacts section of the Associations card on the Overview tab of the Details screen, which is displayed when viewing the Associations card in table view. - [Table View: Associated Cases](https://knowledge.threatconnect.com/docs/table-view-associated-cases.md): This article describes the Associated Cases section of the Associations card on the Overview tab of the Details screen, which is displayed when viewing the Associations card in table view. - [Table View: Potential Associations](https://knowledge.threatconnect.com/docs/table-view-potential-associations.md): This article describes the Potential Associations section of the Associations card on the Overview tab of the Details screen, which is displayed when viewing the Associations card in table view. - [The Associations Tab](https://knowledge.threatconnect.com/docs/the-associations-tab.md): This article describes the Associations tab of the Details screen and the actions you can perform on this screen. - [Best Practices: Cross-Owner Associations](https://knowledge.threatconnect.com/docs/best-practices-cross-owner-associations.md): This article outlines best practices to follow when using ThreatConnect’s cross-owner associations feature to create associations between objects in your Organization and objects in the Communities and Sources to which you have access. - [Accessing the ATT&CK Visualizer](https://knowledge.threatconnect.com/docs/accessing-the-attack-visualizer.md): This article describes how to access the ATT&CK Visualizer in ThreatConnect. - [Standard ATT&CK Views](https://knowledge.threatconnect.com/docs/standard-attack-views.md): This article describes how to create, save, export, and delete standard ATT&CK views using the ThreatConnect ATT&CK Visualizer. It also describes the overlays available for standard ATT&CK views. - [Imported ATT&CK Views](https://knowledge.threatconnect.com/docs/imported-attack-views.md): This article describes how to import ATT&CK views into the ThreatConnect ATT&CK Visualizer. It also describes the overlays available for imported ATT&CK views. - [Visualizing ATT&CK Tactics, Techniques, and Sub-techniques](https://knowledge.threatconnect.com/docs/visualizing-attack-tactics-techniques-and-sub-techniques.md): This article describes the ThreatConnect ATT&CK Visualizer layout and how to view details for specific techniques and sub-techniques. - [Viewing and Managing Saved ATT&CK Views](https://knowledge.threatconnect.com/docs/viewing-and-managing-saved-attack-views.md): This article describes how to view and manage all saved standard and imported ATT&CK views in your Organization on the ATT&CK screen. - [ATT&CK Security Coverage](https://knowledge.threatconnect.com/docs/attack-security-coverage.md): This article describes how Organization Administrators can use the ThreatConnect ATT&CK Visualizer to assign security coverage to techniques and sub-techniques for their Organization. It also describes the Security Coverage overlay for ATT&CK views. - [ATT&CK RQ Financial Impact](https://knowledge.threatconnect.com/docs/attack-rq-financial-impact.md) - [ATT&CK Tags](https://knowledge.threatconnect.com/docs/attack-tags.md): This article describes ATT&CK Tags in ThreatConnect, including how to view them, identify objects to which they are applied, and apply them to objects. It also describes ATT&CK Tag conversion rules and how to configure them. - [Automated Data Services Overview](https://knowledge.threatconnect.com/docs/automated-data-services-overview.md): This article provides an overview of automated data services in ThreatConnect and the corresponding minimum roles and prerequisites for this feature. - [DNS Resolutions](https://knowledge.threatconnect.com/docs/dns-resolutions.md): This article describes the DNS resolution tracking feature for Host and Address Indicators, including how to view DNS resolution history, subdomain resolutions, historic IP address resolutions, and Quad9 observed attempt resolutions. - [IP Geolocation Data](https://knowledge.threatconnect.com/docs/ip-geolocation-data.md): This article describes how to view IP geolocation data for Address and Host Indicators on the Details screen. - [WHOIS Registration Information](https://knowledge.threatconnect.com/docs/whois-registration-information.md): This article describes how to view WHOIS registration information for Host Indicators. - [Dataminr Cyber Pulse Limited Feed](https://knowledge.threatconnect.com/docs/dataminr-cyber-pulse-limited-feed.md): This article describes the Dataminr Cyber Pulse Limited feed in ThreatConnect, which delivers Dataminr Pulse Urgent and Flash Cyber Alerts and their associated metadata and AI context directly into ThreatConnect. - [The Enrichment Tab](https://knowledge.threatconnect.com/docs/the-enrichment-tab.md): This article describes how to view data returned from a third-party enrichment service for an Indicator on the Enrichment tab of its Details screen in ThreatConnect. - [AbuseIPDB Enrichment](https://knowledge.threatconnect.com/docs/abuseipdb-enrichment.md): This article describes how to enable the AbuseIPDB enrichment service in ThreatConnect and view data retrieved from AbuseIPDB on the Enrichment tab of an Indicator’s Details screen. - [DomainTools Enrichment](https://knowledge.threatconnect.com/docs/domaintools-enrichment.md): This article describes how to enable the DomainTools enrichment service in ThreatConnect, view data retrieved from DomainTools on the Enrichment tab of an Indicator’s Details screen, and import Indicators from DomainTools into ThreatConnect. - [Farsight Security Passive DNS Enrichment](https://knowledge.threatconnect.com/docs/farsight-security-passive-dns-enrichment.md): This article describes how to enable the Farsight Security enrichment service in ThreatConnect, view data retrieved from Farsight Security on the Enrichment tab of an Indicator’s Details screen, and import Indicators from Farsight Security. - [Shodan Enrichment](https://knowledge.threatconnect.com/docs/shodan-enrichment.md): This article describes how to enable the Shodan enrichment service in ThreatConnect, view data retrieved from Shodan on the Enrichment tab of an Indicator’s Details screen, and import vulnerabilities from Shodan into ThreatConnect. - [urlscan.io Enrichment](https://knowledge.threatconnect.com/docs/urlscan-io-enrichment.md): This article describes how to enable the urlscan.io enrichment service in ThreatConnect, view data retrieved from urlscan.io on the Enrichment tab of an Indicator’s Details screen, and import Indicators from urlscan.io into ThreatConnect. - [RiskIQ Enrichment](https://knowledge.threatconnect.com/docs/riskiq-enrichment.md): This article describes how to enable the RiskIQ enrichment service in ThreatConnect, view data retrieved from RiskIQ on the Enrichment tab of an Indicator’s Details screen, and import Indicators from RiskIQ into ThreatConnect. - [VirusTotal Enrichment](https://knowledge.threatconnect.com/docs/virustotal-enrichment.md): This article describes how to enable the VirusTotal enrichment service in ThreatConnect, view data retrieved from VirusTotal on the Enrichment tab of an Indicator’s Details screen, and import Indicators from VirusTotal into ThreatConnect. - [Viewing an Object in Threat Graph](https://knowledge.threatconnect.com/docs/viewing-an-object-in-threat-graph.md): The article describes how to view an Indicator, Group, Tag, or Case in Threat Graph. It also provides a summary of the options available when you click on a node in Threat Graph. - [Pivoting in ThreatConnect in Threat Graph](https://knowledge.threatconnect.com/docs/pivoting-in-threatconnect-in-threat-graph.md): This article describes how to pivot on Indicator, Group, Case, and Tag associations that exist in ThreatConnect with the Pivot in ThreatConnect option in Threat Graph. - [Pivoting With CAL in Threat Graph](https://knowledge.threatconnect.com/docs/pivoting-with-cal-in-threat-graph.md): This article describes how to pivot on Indicator and Group relationships that exist in CAL with the Pivot with CAL option in Threat Graph. - [Pivoting on Enrichment Services in Threat Graph](https://knowledge.threatconnect.com/docs/pivoting-on-enrichment-services-in-threat-graph.md): This article describes how to pivot on third-party enrichment service relationships for Indicators with the Enrich option in Threat Graph. - [Adding Associations in Threat Graph](https://knowledge.threatconnect.com/docs/adding-associations-in-threat-graph.md): This article describes how to add associations to Indicators and Groups in Threat Graph. - [Running Playbooks in Threat Graph](https://knowledge.threatconnect.com/docs/running-playbooks-in-threat-graph.md): This article describes how to run an active UserAction Trigger–based Playbook for Indicators that exist in ThreatConnect while using Threat Graph. - [Importing Indicators From Threat Graph](https://knowledge.threatconnect.com/docs/importing-indicators-from-threat-graph.md): This article describes how to import Indicators from Threat Graph into one of your ThreatConnect owners. - [Removing Objects From Threat Graph](https://knowledge.threatconnect.com/docs/removing-objects-from-threat-graph.md): This article describes how to remove Indicator, Group, Case, and Tag nodes from Threat Graph. - [Group Alias Information in Threat Graph](https://knowledge.threatconnect.com/docs/group-alias-information-in-threat-graph.md): This article describes how to view alias information for Groups that CAL knows of and combine Group nodes that share an alias in Threat Graph. - [Viewing Details in Threat Graph](https://knowledge.threatconnect.com/docs/viewing-details-in-threat-graph.md): This article describes how to view details for Indicators, Groups, Cases, and Tags in Threat Graph. - [Adjusting View and Layout in Threat Graph](https://knowledge.threatconnect.com/docs/adjusting-view-and-layout-in-threat-graph.md): This article describes how to adjust the view settings and layout of nodes in Threat Graph. - [Saving, Exporting, and Managing Graphs in Threat Graph](https://knowledge.threatconnect.com/docs/saving-exporting-and-managing-graphs-in-threat-graph.md): This article describes how to save, export, and manage a graph while it is open in Threat Graph. - [Viewing All Graphs Saved in Threat Graph](https://knowledge.threatconnect.com/docs/viewing-all-graphs-saved-in-threat-graph.md): This article describes the Graph screen in ThreatConnect, which is where you can view and manage all graphs you and other users in your Organization have saved in Threat Graph. - [False Positives Overview](https://knowledge.threatconnect.com/docs/false-positives-overview.md): This article describes false positives in ThreatConnect and the corresponding minimum role and prerequisites for this feature. - [Viewing and Reporting False Positives](https://knowledge.threatconnect.com/docs/viewing-and-reporting-false-positives.md): This article describes how to view and report false positives for an Indicator via its Details screen. - [Including False Positives Reported by API Users](https://knowledge.threatconnect.com/docs/including-false-positives-reported-by-api-users.md): This article describes how Organization Administrators can enable false positive data provided by API users to be included in the Observations/False Positives card for Indicators. - [Setting an Event Status to False Positive](https://knowledge.threatconnect.com/docs/setting-an-event-status-to-false-positive.md): This article describes how to set the status of an Event Group to False Positive and, if desired, report Indicators associated to the Group as false positives. - [Indicator Status](https://knowledge.threatconnect.com/docs/indicator-status.md): This article describes Indicator Status in ThreatConnect, including viewing and setting Indicator Status, locally set vs. CAL-determined status, processes that determine Indicator Status (including CAL status), and status locks. - [Best Practices: Intelligence Requirements](https://knowledge.threatconnect.com/docs/best-practices-intelligence-requirements.md): This article outlines best practices to follow when creating Intelligence Requirements in ThreatConnect. - [Best Practices: Keywords for Intelligence Requirements](https://knowledge.threatconnect.com/docs/best-practices-keywords-for-intelligence-requirements.md): This article outlines best practices to follow when defining Intelligence Requirement keyword queries in ThreatConnect. - [Intelligence Requirement Categories](https://knowledge.threatconnect.com/docs/intelligence-requirement-categories.md): This article describes how to view, create, and manage Intelligence Requirement categories on the System Settings screen in ThreatConnect (System Administrators only). - [Creating Intelligence Requirements](https://knowledge.threatconnect.com/docs/creating-intelligence-requirements.md): This article describes how to create Intelligence Requirements in ThreatConnect. - [Viewing Intelligence Requirement Details](https://knowledge.threatconnect.com/docs/viewing-intelligence-requirement-details.md): This article describes how to view details for Intelligence Requirements in ThreatConnect. - [MITRE ATT&CK AI Classification in ThreatConnect](https://knowledge.threatconnect.com/docs/mitre-attack-ai-classification-in-threatconnect.md): This article explains how the MITRE ATT&CK AI classification model works in ThreatConnect, describes the areas in ThreatConnect that leverage the model, and lists the techniques and sub-techniques used in the model. - [Modeling File Behavior](https://knowledge.threatconnect.com/docs/modeling-file-behavior.md): This article discusses how to view a File Indicator's behavior model, defines the various behavior types, and describes how to create File Indicator behavior associations. - [OSINT and CAL Feeds](https://knowledge.threatconnect.com/docs/osint-and-cal-feeds.md): This article provides a list of open-source intelligence (OSINT) and CAL feeds included in ThreatConnect by default. - [Pivoting on Data](https://knowledge.threatconnect.com/docs/pivoting-on-data.md): This article describes how to pivot from Indicators, Groups, Tags, and Attributes in ThreatConnect. - [Private Indicators](https://knowledge.threatconnect.com/docs/private-indicators.md): This article describes how to mark an Indicator as private in ThreatConnect. - [Tag Normalization](https://knowledge.threatconnect.com/docs/tag-normalization.md): This article describes Tag normalization in ThreatConnect, including how to create and manage Tag normalization rules, view details for main Tags, and identify when a main Tag is applied to an object. - [The Feed Explorer](https://knowledge.threatconnect.com/docs/the-feed-explorer.md): This article describes the Feed Explorer, which provides information on all open-source intelligence and CAL feeds in ThreatConnect, including associated metric data and report cards. - [The "Last Modified" Date](https://knowledge.threatconnect.com/docs/the-last-modified-date.md): This article describes the areas in ThreatConnect where you can view the date and time when an object was last modified. It also details whether certain actions you can perform update the date and time when an object was last modified. - [Installing and Logging Into ThreatConnect Intelligence Anywhere](https://knowledge.threatconnect.com/docs/installing-and-logging-into-threatconnect-intelligence-anywhere.md): This article describes how to add ThreatConnect Intelligence Anywhere as an extension for your web browser and how to authenticate to it with your ThreatConnect user account. - [Configuring ThreatConnect Intelligence Anywhere](https://knowledge.threatconnect.com/docs/configuring-threatconnect-intelligence-anywhere.md): This article describes how to configure ThreatConnect Intelligence Anywhere after installing and logging into it. - [Scanning Online Resources With ThreatConnect Intelligence Anywhere](https://knowledge.threatconnect.com/docs/scanning-online-resources-with-threatconnect-intelligence-anywhere.md): This article describes how to scan online resources with ThreatConnect Intelligence Anywhere. - [Reviewing ThreatConnect Intelligence Anywhere Scan Results](https://knowledge.threatconnect.com/docs/reviewing-threatconnect-intelligence-anywhere-scan-results.md): This article describes how to review scan results provided by ThreatConnect Intelligence Anywhere after scanning an online resource. - [Importing Potential Indicators Found With ThreatConnect Intelligence Anywhere](https://knowledge.threatconnect.com/docs/importing-potential-indicators-found-with-threatconnect-intelligence-anywhere.md): This article describes how to import potential Indicators found during a ThreatConnect Intelligence Anywhere scan into your ThreatConnect instance. - [Running Advanced Searches With TQL](https://knowledge.threatconnect.com/docs/running-advanced-searches-with-tql.md): This article describes how to run advanced searches using TQL queries, save TQL queries, and manage saved TQL queries. - [Constructing Query Expressions](https://knowledge.threatconnect.com/docs/constructing-query-expressions.md): This article describes how to create ThreatConnect Query Language (TQL) queries and provides some sample TQL queries you can use in ThreatConnect. - [TQL Operators and Parameters](https://knowledge.threatconnect.com/docs/tql-operators-and-parameters.md): This article provides a list of all ThreatConnect Query Language (TQL) operators and parameters. - [TQL Generator](https://knowledge.threatconnect.com/docs/tql-generator.md): This article describes the TQL Generator in ThreatConnect, including how to generate TQL queries with it and share feedback about results to help improve the feature. - [Dataminr Cyber Pulse Limited Feed](https://knowledge.threatconnect.com/docs/dataminr-cyber-pulse-limited-feed-1.md): This article describes the Dataminr Cyber Pulse Limited feed in ThreatConnect, which delivers Dataminr Pulse Urgent and Flash Cyber Alerts and their associated metadata and AI context directly into ThreatConnect. - [Dataminr Pulse Alerts Engine Integration User Guide](https://knowledge.threatconnect.com/docs/dataminr-pulse-alerts-engine-integration-user-guide-1.md): This article is a user guide for the Dataminr Pulse Alerts Engine App in ThreatConnect. - [Cases Metrics Overview](https://knowledge.threatconnect.com/docs/cases-metrics-overview.md): This article provides an overview of Cases metrics in ThreatConnect and the corresponding minimum roles and prerequisites for this feature. - [Adding a Cases Metric Card to a Dashboard](https://knowledge.threatconnect.com/docs/adding-a-cases-metric-card-to-a-dashboard.md): This article describes how to add a new Cases Metric card to a custom dashboard. - [Active Cases](https://knowledge.threatconnect.com/docs/active-cases.md): This article describes how to add and configure the Active Cases metric card in a custom dashboard. - [Analyst Workload](https://knowledge.threatconnect.com/docs/analyst-workload.md): This article describes how to add and configure the Analyst Workload metric card in a custom dashboard. - [False Positives](https://knowledge.threatconnect.com/docs/false-positives-1.md): This article describes how to add and configure the False Positives metric card in a custom dashboard. - [MTTD](https://knowledge.threatconnect.com/docs/mttd.md): This article describes how to add and configure the MTTD metric card in a custom dashboard. - [MTTD Average](https://knowledge.threatconnect.com/docs/mttd-average.md): This article describes how to add and configure the MTTD Average metric card in a custom dashboard. - [MTTR](https://knowledge.threatconnect.com/docs/mttr.md): This article describes how to add and configure the MTTR metric card in a custom dashboard. - [MTTR Average](https://knowledge.threatconnect.com/docs/mttr-average.md): This article describes how to add and configure the MTTR Average metric card in a custom dashboard. - [Top 10 Case Closing Analyst](https://knowledge.threatconnect.com/docs/top-10-case-closing-analyst.md): This article describes how to add and configure the Top 10 Case Closing Analyst metric card in a custom dashboard. - [Unassigned Cases](https://knowledge.threatconnect.com/docs/unassigned-cases.md): This article describes how to add and configure the Unassigned Cases metric card in a custom dashboard. - [Custom Metrics](https://knowledge.threatconnect.com/docs/custom-metrics.md): This article describes how to create custom metrics on the Organization Settings screen with an Organization Administrator account, and via the ThreatConnect v2 API with an API user account. It also describes how to add data to a custom metric. - [Viewing Dashboards](https://knowledge.threatconnect.com/docs/viewing-dashboards.md): This article describes how to view a dashboard in ThreatConnect. - [Cloud Built-In Dashboards](https://knowledge.threatconnect.com/docs/cloud-built-in-dashboards.md): This article describes built-in dashboards available to users on Cloud and Dedicated Cloud instances of ThreatConnect. - [Creating Dashboards](https://knowledge.threatconnect.com/docs/creating-dashboards.md): This article describes how to create custom dashboards in ThreatConnect instances where this feature is turned on. - [Adding Widget Cards to Dashboards](https://knowledge.threatconnect.com/docs/adding-widget-cards-to-dashboards.md): This article describes how to add Widget cards to custom dashboards. - [Adding Metric Cards to Dashboards](https://knowledge.threatconnect.com/docs/adding-metric-cards-to-dashboards.md): This article describes how to add Metric cards to custom dashboards. - [Adding Query Cards to Dashboards](https://knowledge.threatconnect.com/docs/adding-query-cards-to-dashboards.md): This article describes how to add Query cards to custom dashboards. - [Editing Dashboard Layout](https://knowledge.threatconnect.com/docs/editing-dashboard-layout.md): This article describes how to customize a dashboard's layout, including moving and resizing dashboard cards. - [Managing Dashboard Cards](https://knowledge.threatconnect.com/docs/managing-dashboard-cards.md): This article describes how to edit, rename, and delete dashboard cards. It also describes how to select owners to display data from on a dashboard card. - [Dashboard Administration](https://knowledge.threatconnect.com/docs/dashboard-administration.md): This article describes how to access the dashboard administration features on the Dashboard screen and the function of each administrative option. - [Exporting and Importing Dashboards](https://knowledge.threatconnect.com/docs/exporting-and-importing-dashboards.md): This article describes how to export dashboards in your ThreatConnect instance and import dashboards using a .tdb file. - [Downloading a PDF for a Group](https://knowledge.threatconnect.com/docs/downloading-a-pdf-for-a-group.md): This article describes how to download a PDF file for supported Group types in ThreatConnect. This PDF can be shared with management, customers, or members of your team for the purpose of describing the Group to others. - [Creating a Report](https://knowledge.threatconnect.com/docs/creating-a-report.md): This article describes the different ways you can create a report in ThreatConnect. - [Adding Group Data to a Report](https://knowledge.threatconnect.com/docs/adding-group-data-to-a-report.md): This article describes how to add Group Data sections to a report in ThreatConnect. - [Adding Case Data to a Report](https://knowledge.threatconnect.com/docs/adding-case-data-to-a-report.md): This article describes how to add Case Data sections to a report in ThreatConnect. - [Adding Basic Elements to a Report](https://knowledge.threatconnect.com/docs/adding-basic-elements-to-a-report.md): This article describes how to add Basic Elements sections to a report in ThreatConnect. - [Adding Layout Elements to a Report](https://knowledge.threatconnect.com/docs/adding-layout-elements-to-a-report.md): This article describes how to add Layout Elements sections to a report in ThreatConnect. - [Organizing, Editing, Previewing, and Deleting a Report](https://knowledge.threatconnect.com/docs/organizing-editing-previewing-and-deleting-a-report.md): This article describes how to organize, edit, preview, and delete a report in ThreatConnect. - [Saving, Publishing, and Exporting a Report](https://knowledge.threatconnect.com/docs/saving-publishing-and-exporting-a-report.md): This article describes how to save, publish, and export a report in ThreatConnect. - [Report Templates](https://knowledge.threatconnect.com/docs/report-templates.md): This article describes how to create, manage, and use a report template in ThreatConnect. - [Viewing and Managing All Saved Reports and Templates](https://knowledge.threatconnect.com/docs/viewing-and-managing-all-saved-reports-and-templates.md): This article details the Reporting screen in ThreatConnect, which is where you can view and manage all reports and templates you and other users in your Organization have saved. - [Searching All Object Types](https://knowledge.threatconnect.com/docs/searching-all-object-types.md): This article describes how to search your ThreatConnect data from the Search screen. It also details how the search engine handles searches for defanged Indicators. - [Viewing Search Results for All Object Types](https://knowledge.threatconnect.com/docs/viewing-search-results-for-all-object-types.md): This article describes how to view, manage, sort, and filter search results on the Search: All Object Types screen in ThreatConnect. - [Bulk Searching Indicators](https://knowledge.threatconnect.com/docs/bulk-searching-indicators.md): This article describes how to run a bulk Indicator search in ThreatConnect and view, consolidate, manage, sort, and filter the corresponding search results. - [Searching Groups](https://knowledge.threatconnect.com/docs/searching-groups.md): This article describes how to use the Search: Groups screen to view, search, export, delete, and analyze Groups in your ThreatConnect owners. - [Searching Indicators](https://knowledge.threatconnect.com/docs/searching-indicators.md): This article describes how to use the Search: Indicators screen to view, search, export, delete, and analyze Indicators in your ThreatConnect owners. - [Searching Intelligence Requirements](https://knowledge.threatconnect.com/docs/searching-intelligence-requirements.md): This article describes how to use the Search: Intelligence Requirements screen to view, search, and analyze Intelligence Requirements in your Organization in ThreatConnect. - [Searching Tags](https://knowledge.threatconnect.com/docs/searching-tags.md): This article describes how to use the Search: Tags screen to view, search, and analyze standard Tags in your ThreatConnect owners and ATT&CK Tags. It also describes how to delete standard Tags on the Search: Tags screen. - [Searching Victim Assets](https://knowledge.threatconnect.com/docs/searching-victim-assets.md): This article describes how to use the Search: Victim Assets screen to view, search, delete, and analyze Victim Assets in your ThreatConnect owners. - [Searching Victims](https://knowledge.threatconnect.com/docs/searching-victims.md): This article describes how to use the Search: Victims screen to view, search, delete, and analyze Victims in your ThreatConnect owners. - [Saved Search Queries](https://knowledge.threatconnect.com/docs/saved-search-queries.md): This article describes how to save, view, edit, delete, and run saved queries when using the object filters on the Search screen. - [Searching Your Data (Legacy)](https://knowledge.threatconnect.com/docs/searching-your-data-legacy.md): This article describes how to search your ThreatConnect data from the Search drawer. It also details how the legacy search engine handles searches for defanged Indicators. - [Search Filters (Legacy)](https://knowledge.threatconnect.com/docs/search-filters-legacy.md): This article describes how to filter search results on the Search drawer in ThreatConnect. - [Search Results (Legacy)](https://knowledge.threatconnect.com/docs/search-results-legacy.md): This article describes the types of search results returned when using the Search drawer in ThreatConnect. - [API Documentation](https://knowledge.threatconnect.com/docs/api-documentation.md): This article provides links to documentation for the ThreatConnect v3 and v2 APIs. - [App Builder Overview](https://knowledge.threatconnect.com/docs/app-builder-overview.md): This article provides an overview of the App Builder in ThreatConnect and the corresponding minimum roles and prerequisites for this feature. - [The Apps Screen](https://knowledge.threatconnect.com/docs/the-apps-screen.md): This article details the Apps screen in ThreatConnect (i.e., the screen displayed when you select App Builder from the Playbooks dropdown on the top navigation bar). - [Administrative Functions for Projects and Apps](https://knowledge.threatconnect.com/docs/administrative-functions-for-projects-and-apps.md): This article describes how to create a new project, clone an App or project, import a project, and edit, download, or delete an existing project. - [The App Builder Screen](https://knowledge.threatconnect.com/docs/the-app-builder-screen.md): This article describes how to adjust the layout of the App Builder screen, edit the name of an App project, and the options available in the ACTIONS menu. - [Summary Tab](https://knowledge.threatconnect.com/docs/summary-tab.md): This article describes the Summary tab of the App Builder screen. - [Metadata Tab](https://knowledge.threatconnect.com/docs/metadata-tab.md): This article describes the Metadata tab of the App Builder screen. - [Contents Tab](https://knowledge.threatconnect.com/docs/contents-tab.md): This article describes the Contents tab of the App Builder screen, including how to create and manage files and directories in an App project. - [Code Editor](https://knowledge.threatconnect.com/docs/code-editor.md): This article describes the Code Editor of the App Builder screen. - [Snippets Tab](https://knowledge.threatconnect.com/docs/snippets-tab.md): This article describes the Snippets tab of the App Builder screen, including how to insert and create snippets and manage user-created snippets in an App project. - [Inputs Tab](https://knowledge.threatconnect.com/docs/inputs-tab.md): This article describes the Inputs tab of the App Builder screen, including how to create and manage input parameters in an App project. - [Outputs Tab](https://knowledge.threatconnect.com/docs/outputs-tab.md): This article describes the Outputs tab of the App Builder screen, including how to create and manage output variables in an App project. - [Retry Tab](https://knowledge.threatconnect.com/docs/retry-tab.md): This article describes the Retry tab of the App Builder screen. - [Source Control Tab](https://knowledge.threatconnect.com/docs/source-control-tab.md): This article describes the Source Control tab of the App Builder screen, including how to create commits, comment on commits, and revert to previous commits. - [Validations Tab](https://knowledge.threatconnect.com/docs/validations-tab.md): This article describes the Validations tab of the App Builder screen. - [App Builder Settings](https://knowledge.threatconnect.com/docs/app-builder-settings.md): This article describes the options available in the Settings menu of the App Builder screen. - [Building an App](https://knowledge.threatconnect.com/docs/building-an-app.md): This article describes how to build an App project and view a log of the most recent build in the Build Log tab of the App Builder screen. - [Debugging and Testing an App](https://knowledge.threatconnect.com/docs/debugging-and-testing-an-app.md): This article describes how to use the Live Debug feature to debug and test an App in the App Builder. - [Releasing an App](https://knowledge.threatconnect.com/docs/releasing-an-app.md): This article describes how Organization Administrators can release an App after it has been built and debugged in the App Builder. - [ThreatConnect Domain Thrasher](https://knowledge.threatconnect.com/docs/threatconnect-domain-thrasher.md): This article describes how to install, configure, and use ThreatConnect Domain Thrasher, which enables you to automate and track proactive investigations into registered domain variants for your organization. - [Cisco Umbrella Investigate Spaces User Guide](https://knowledge.threatconnect.com/docs/cisco-umbrella-investigate-spaces-user-guide.md): This article provides a PDF file of the Cisco Umbrella Investigate Spaces User Guide for ThreatConnect. - [Malformity Labs Maltego Integration](https://knowledge.threatconnect.com/docs/malformity-labs-maltego-integration.md): This article provides a PDF file of the Malformity Labs Maltego Integration documentation for ThreatConnect. - [Silent Push Integration Installation and Configuration Guide](https://knowledge.threatconnect.com/docs/silent-push-integration-installation-and-configuration-guide.md): This article is a user guide for the Silent Push integration with ThreatConnect. - [ThreatConnect App for ServiceNow Security Operations User Guide](https://knowledge.threatconnect.com/docs/threatconnect-app-for-servicenow-security-operations-user-guide.md): This article provides a PDF file of the ThreatConnect App for ServiceNow Security Operations User Guide for ThreatConnect. - [ThreatConnect VirusTotal Spaces App User Guide](https://knowledge.threatconnect.com/docs/threatconnect-virustotal-spaces-app-user-guide.md): This article provides a PDF file of the ThreatConnect VirusTotal Spaces App User Guide. - [ThreatConnect Threat Intelligence Enrichment API Plugin for Microsoft Security Copilot User Guide](https://knowledge.threatconnect.com/docs/threatconnect-threat-intelligence-enrichment-api-plugin-for-microsoft-security-copilot-user-guide.md): This article is a user guide for the ThreatConnect Threat Intelligence Enrichment API plugin for Microsoft Security Copilot. - [CrowdStrike Falcon Insight Extract Integration Configuration Guide](https://knowledge.threatconnect.com/docs/crowdstrike-falcon-insight-extract-integration-configuration-guide.md): This article provides a PDF file of the CrowdStrike Falcon Insight Extract Integration Configuration Guide for ThreatConnect. - [Microsoft Defender for Endpoint Integration User Guide](https://knowledge.threatconnect.com/docs/microsoft-defender-for-endpoint-integration-user-guide.md): This article provides a PDF file of the Microsoft Defender for Endpoint Integration User Guide for ThreatConnect. - [Tanium Connect Reputation Blacklist Integration Configuration Guide](https://knowledge.threatconnect.com/docs/tanium-connect-reputation-blacklist-integration-configuration-guide.md): This article provides a PDF file of the Tanium Connect Reputation Blacklist Integration Configuration Guide for ThreatConnect. - [Tanium Threat Response - Indicators Integration Configuration Guide](https://knowledge.threatconnect.com/docs/tanium-threat-response-indicators-integration-configuration-guide.md): This article provides a PDF file of the Tanium Threat Response - Indicators Integration Configuration Guide for ThreatConnect. - [Tanium Threat Response - Signatures Integration Configuration Guide](https://knowledge.threatconnect.com/docs/tanium-threat-response-signatures-integration-configuration-guide.md): This article provides a PDF file of the Tanium Threat Response - Signatures Integration Configuration Guide for ThreatConnect. - [FireEye Helix Log Analytics Integration Configuration Guide](https://knowledge.threatconnect.com/docs/fireeye-helix-log-analytics-integration-configuration-guide.md): This article provides a PDF file of the FireEye Helix Log Analytics Integration Configuration Guide for ThreatConnect. - [Microsoft Graph Security Threat Indicators Integration User Guide](https://knowledge.threatconnect.com/docs/microsoft-graph-security-threat-indicators-integration-user-guide.md): This article is a user guide for the Microsoft Graph Security Threat Indicators app in ThreatConnect. - [Cisco Umbrella Integration Configuration Guide](https://knowledge.threatconnect.com/docs/cisco-umbrella-integration-configuration-guide.md): This article provides a PDF file of the Cisco Umbrella Integration Configuration Guide for ThreatConnect. - [Palo Alto Networks NGFW Integration Installation and Configuration Guide](https://knowledge.threatconnect.com/docs/palo-alto-networks-ngfw-integration-installation-and-configuration-guide.md): This article provides a PDF file of the Palo Alto Networks NGFW Integration Installation and Configuration Guide for ThreatConnect. - [Zscaler Internet Access Integration User Guide](https://knowledge.threatconnect.com/docs/zscaler-internet-access-integration-user-guide.md): This article provides a PDF file of the Zscaler Internet Access Integration User Guide for ThreatConnect. - [MITRE ATT&CK App Overview](https://knowledge.threatconnect.com/docs/mitre-attack-app-overview.md): This article provides an overview of the MITRE ATT&CK App and Source feed in ThreatConnect and the corresponding minimum roles and prerequisites for this feature. - [MITRE ATT&CK Deployment and Configuration Overview](https://knowledge.threatconnect.com/docs/mitre-attack-deployment-and-configuration-overview.md): This article provides an overview of the MITRE ATT&CK deployment and configuration process your administrator must perform to be able to access MITRE ATT&CK data objects in your Organization. - [Installing the MITRE ATT&CK App](https://knowledge.threatconnect.com/docs/installing-the-mitre-attack-app.md): This article describes how System Administrators can install the MITRE ATT&CK 2.0.x App from TC Exchange. - [Deploying the MITRE ATT&CK Source Feed](https://knowledge.threatconnect.com/docs/deploying-the-mitre-attack-source-feed.md): This article describes how System Administrators can deploy the MITRE ATT&CK Source Feed after installing the MITRE ATT&CK 2.0.x App. - [MITRE ATT&CK Manual Job Configuration (Advanced Users Only)](https://knowledge.threatconnect.com/docs/mitre-attack-manual-job-configuration.md): This article describes how Organization Administrators can configure a Job for the MITRE ATT&CK App manually after a System Administrator has installed the App. - [Adding the MITRE ATT&CK Source to Multiple Organizations](https://knowledge.threatconnect.com/docs/adding-the-mitre-attack-source-to-multiple-organizations.md): This article describes how to add the MITRE ATT&CK Source to multiple Organizations after it has been deployed to an Organization on a ThreatConnect instance. - [MITRE ATT&CK App Data Mappings](https://knowledge.threatconnect.com/docs/mitre-attack-app-data-mappings.md): This article provides data mappings for the MITRE ATT&CK App and describes how each ThreatConnect object created by the App corresponds to the information provided for the object in the MITRE ATT&CK database. - [Viewing MITRE ATT&CK App Data](https://knowledge.threatconnect.com/docs/viewing-mitre-attack-app-data.md): This article describes how to view data created by the MITRE ATT&CK App on the Browse screen in ThreatConnect. - [Enriching Data With Tags From the MITRE ATT&CK Source](https://knowledge.threatconnect.com/docs/enriching-data-with-tags-from-the-mitre-attack-source.md): This article describes how to copy Tags from the MITRE ATT&CK Source to your Organization and use them to enrich ThreatConnect data in your Organization. - [ThreatConnect Activity Pack for ServiceNow Orchestration User Guide](https://knowledge.threatconnect.com/docs/threatconnect-activity-pack-for-servicenow-orchestration-user-guide.md): This article provides a PDF file of the ThreatConnect Activity Pack for ServiceNow Orchestration User Guide for ThreatConnect. - [Accenture DeepSight Intelligence Integration Installation and Configuration Guide](https://knowledge.threatconnect.com/docs/accenture-deepsight-intelligence-integration-installation-and-configuration-guide.md): This article provides a PDF file of the Accenture DeepSight Intelligence Integration and Configuration Guide for ThreatConnect. - [Accenture iDefense Intelligence Engine Integration User Guide](https://knowledge.threatconnect.com/docs/accenture-idefense-intelligence-engine-integration-user-guide.md): This article is a user guide for the Accenture iDefense Intelligence Engine integration with ThreatConnect. - [BAE Systems Threat Intelligence Integration Configuration Guide](https://knowledge.threatconnect.com/docs/bae-systems-threat-intelligence-integration-configuration-guide.md): This article provides a PDF file of the BAE Systems Threat Intelligence Integration Configuration Guide for ThreatConnect. - [Booz Allen Hamilton Cyber4Sight ThreatBase Installation Guide](https://knowledge.threatconnect.com/docs/booz-allen-hamilton-cyber4sight-threatbase-installation-guide.md): This article provides a PDF file of the Booz Allen Hamilton Cyber4Sight ThreatBase Installation Guide for ThreatConnect. - [CrowdStrike Falcon Intelligence Engine Integration User Guide](https://knowledge.threatconnect.com/docs/crowdstrike-falcon-intelligence-engine-integration-user-guide.md): This article is a user guide for the CrowdStrike Falcon Intelligence Engine integration with ThreatConnect. - [Dataminr Pulse Alerts Engine Integration User Guide](https://knowledge.threatconnect.com/docs/dataminr-pulse-alerts-engine-integration-user-guide.md): This article is a user guide for the Dataminr Pulse Alerts Engine App in ThreatConnect. - [Digital Shadows SearchLight Integration Configuration Guide](https://knowledge.threatconnect.com/docs/digital-shadows-searchlight-integration-configuration-guide.md): This article is a configuration guide for the Digital Shadows SearchLight integration with ThreatConnect. - [Dragos WorldView Intelligence Engine Integration User Guide](https://knowledge.threatconnect.com/docs/dragos-worldview-intelligence-engine-integration-user-guide.md): This article is a user guide for the Dragos WorldView Intelligence Engine integration with ThreatConnect. - [Feedly Intelligence Engine Integration User Guide](https://knowledge.threatconnect.com/docs/feedly-intelligence-engine-integration-user-guide.md): This article is a user guide for the Feedly Intelligence Engine App in ThreatConnect. - [Fidelis Network Extract Integration Configuration Guide](https://knowledge.threatconnect.com/docs/fidelis-network-extract-integration-configuration-guide.md): This article provides a PDF file of the Fidelis Network Extract Integration Configuration Guide for ThreatConnect. - [Flashpoint Ignite Threat Intelligence Engine Integration User Guide](https://knowledge.threatconnect.com/docs/flashpoint-ignite-threat-intelligence-engine-integration-user-guide.md): This article is a user guide for the Flashpoint Ignite Threat Intelligence Engine App in ThreatConnect. - [FS-ISAC Integration Installation and Configuration Guide](https://knowledge.threatconnect.com/docs/fs-isac-integration-installation-and-configuration-guide.md): This article provides a PDF file of the FS-ISAC Integration Installation and Configuration Guide for ThreatConnect. - [Google Threat Intelligence Integration User Guide](https://knowledge.threatconnect.com/docs/google-threat-intelligence-integration-user-guide.md): This article is a user guide for the Google Threat Intelligence app in ThreatConnect. - [Intel 471 Intelligence Engine Integration User Guide](https://knowledge.threatconnect.com/docs/intel-471-intelligence-engine-integration-user-guide.md): This article is a user guide for the Intel 471 Intelligence Engine integration with ThreatConnect. - [Intel 471 Adversary Intelligence Integration Configuration Guide](https://knowledge.threatconnect.com/docs/intel-471-adversary-intelligence-integration-configuration-guide.md): This article provides a PDF file of the Intel 471 Adversary Intelligence Integration Configuration Guide for ThreatConnect. - [Intel 471 Malware Intelligence Integration Configuration Guide](https://knowledge.threatconnect.com/docs/intel-471-malware-intelligence-integration-configuration-guide.md): This article provides a PDF file of the Intel 471 Malware Intelligence Integration Configuration Guide for ThreatConnect. - [Intel 471 Vulnerability Intelligence Integration Configuration Guide](https://knowledge.threatconnect.com/docs/intel-471-vulnerability-intelligence-integration-configuration-guide.md): This article provides a PDF file of the Intel 471 Vulnerability Intelligence Integration Configuration Guide for ThreatConnect. - [Mandiant Advantage Threat Intelligence Engine Integration Configuration Guide](https://knowledge.threatconnect.com/docs/mandiant-advantage-threat-intelligence-engine-integration-configuration-guide.md): This article is a configuration guide for the Mandiant Advantage Threat Intelligence Engine integration with ThreatConnect. - [Microsoft Defender Threat Intelligence Integration User Guide](https://knowledge.threatconnect.com/docs/microsoft-defender-threat-intelligence-integration-user-guide.md): This article is a user guide for the Microsoft Defender Threat Intelligence App in ThreatConnect. - [MISP Import Integration Configuration Guide](https://knowledge.threatconnect.com/docs/misp-import-integration-configuration-guide.md): This article provides a PDF file of the MISP Import Integration Configuration Guide for ThreatConnect. - [PhishMe Intelligence Integration](https://knowledge.threatconnect.com/docs/phishme-intelligence-integration.md): This article provides a PDF file of the PhishMe Integration Brief for PhishMe Intelligence and ThreatConnect. - [Proofpoint ET Intelligence Reputation List Integration User Guide](https://knowledge.threatconnect.com/docs/proofpoint-et-intelligence-reputation-list-integration-user-guide.md): This article provides a PDF file of the Proofpoint ET Intelligence Reputation List Integration User Guide for ThreatConnect. - [Proofpoint ET Pro Signatures Integration Configuration Guide](https://knowledge.threatconnect.com/docs/proofpoint-et-pro-signatures-integration-configuration-guide.md): This article provides a PDF file of the Proofpoint ET Pro Signatures Integration Configuration Guide for ThreatConnect. - [Threat Intelligence Engine for Recorded Future Integration User Guide](https://knowledge.threatconnect.com/docs/threat-intelligence-engine-for-recorded-future-integration-user-guide.md): This article is a user guide for the Threat Intelligence Engine for Recorded Future app in ThreatConnect. - [Recorded Future Intelligence Engine Integration User Guide Version 1](https://knowledge.threatconnect.com/docs/recorded-future-intelligence-engine-integration-user-guide-version-1.md): This article is a user guide for Software Version 1.0 (deprecated) of the Recorded Future Intelligence Engine integration with ThreatConnect. - [Recorded Future Risk List Integration Installation and Configuration Guide](https://knowledge.threatconnect.com/docs/recorded-future-risk-list-integration-installation-and-configuration-guide.md): This article provides a PDF file of the Recorded Future Risk List Integration Installation and Configuration Guide for ThreatConnect. - [Secureworks Attacker Database Integration Configuration Guide](https://knowledge.threatconnect.com/docs/secureworks-attacker-database-integration-configuration-guide.md): This article provides a PDF file of the Secureworks Attacker Database Integration Configuration Guide for ThreatConnect. - [Wiz Cloud Security Intelligence Engine Integration User Guide](https://knowledge.threatconnect.com/docs/wiz-cloud-security-intelligence-engine-integration-user-guide.md): This article is a user guide for the Wiz Cloud Security Intelligence Engine App in ThreatConnect. - [Amazon GuardDuty Integration Configuration Guide](https://knowledge.threatconnect.com/docs/amazon-guardduty-integration-configuration-guide.md): This article provides a PDF file of the Amazon GuardDuty Integration Configuration Guide for ThreatConnect. - [Elastic Security Integration User Guide](https://knowledge.threatconnect.com/docs/elastic-security-integration-user-guide.md): This article is a user guide for the Elastic Security ThreatConnect integration. - [IBM QRadar App for ThreatConnect User Guide](https://knowledge.threatconnect.com/docs/ibm-qradar-app-for-threatconnect-user-guide.md): This article provides a PDF file of the IBM QRadar App for ThreatConnect User Guide. - [ThreatConnect App for IBM QRadar User Guide](https://knowledge.threatconnect.com/docs/threatconnect-app-for-ibm-qradar-user-guide.md): This article provides a PDF file of the ThreatConnect App for IBM QRadar User Guide. - [Micro Focus ArcSight ESM - CEF Integration Installation and Configuration Guide](https://knowledge.threatconnect.com/docs/micro-focus-arcsight-esm-cef-integration-installation-and-configuration-guide.md): This article provides a PDF file of the Micro Focus ArcSight ESM - CEF Integration Installation and Configuration Guide for ThreatConnect. - [Microsoft Sentinel Integration User Guide](https://knowledge.threatconnect.com/docs/microsoft-sentinel-integration-user-guide.md): This article is a user guide for the Microsoft Sentinel integration with ThreatConnect. - [NetWitness Response Action Proxy With CrowdStrike Falcon Insight User Guide](https://knowledge.threatconnect.com/docs/netwitness-response-action-proxy-with-crowdstrike-falcon-insight-user-guide.md): This article is a user guide for the NetWitness Response Action Proxy integration in ThreatConnect. - [RSA Netwitness Intel Feeds Implementation Guide](https://knowledge.threatconnect.com/docs/rsa-netwitness-intel-feeds-implementation-guide.md): This article provides a link to the RSA Netwitness Intel Feeds Implementation Guide for ThreatConnect. - [ThreatConnect Application for Splunk User Guide](https://knowledge.threatconnect.com/docs/threatconnect-application-for-splunk-user-guide.md): This article provides PDF files of previous versions of the ThreatConnect Application for Splunk User Guide. It also provides a link to documentation for the most recent version of the Splunk integration. - [ThreatConnect SmartResponse Plugin for LogRhythm User Guide](https://knowledge.threatconnect.com/docs/threatconnect-smartresponse-plugin-for-logrhythm-user-guide.md): This article provides a PDF file of the ThreatConnect SmartResponse Plugin for LogRhythm User Guide. - [Spaces Overview](https://knowledge.threatconnect.com/docs/spaces-overview.md): This article provides an overview of the Spaces feature in ThreatConnect and the corresponding minimum roles and prerequisites for this feature. - [Central Spaces](https://knowledge.threatconnect.com/docs/central-spaces.md): The article demonstrates how to create a Central Space and configure an App for the Space. - [Contextually Aware Spaces](https://knowledge.threatconnect.com/docs/contextually-aware-spaces.md): The article describes how to add and configure a Contextually Aware Spaces App for an Indicator or Group in ThreatConnect. It also describes how to delete a Contextually Aware Spaces App from the Spaces tab of the Details screen for an object. - [Menu Spaces](https://knowledge.threatconnect.com/docs/menu-spaces.md): This article describes Menu Spaces in ThreatConnect, including how to add a Menu Space to your profile and delete Menu Spaces added to your profile. - [Batch Import Spaces User Guide](https://knowledge.threatconnect.com/docs/batch-import-spaces-user-guide.md): This article provides a PDF file of the Batch Import Spaces User Guide for ThreatConnect. - [Bulk Victim Create Configuration User Guide](https://knowledge.threatconnect.com/docs/bulk-victim-create-configuration-user-guide.md): This article provides a PDF file of the Bulk Victim Create Configuration User Guide for ThreatConnect. - [Domain-Spinning Workbench](https://knowledge.threatconnect.com/docs/domain-spinning-workbench.md): This article describes the ThreatConnect Domain-Spinning Workbench App. It covers the algorithms that you can choose from for squat identification, and explains how to install, configure, and use the App. - [ThreatConnect Domain-Spinning Workbench Installation and Configuration Guide](https://knowledge.threatconnect.com/docs/threatconnect-domain-spinning-workbench-installation-and-configuration-guide.md): This article provides a PDF file of the ThreatConnect Domain-Spinning Workbench Installation and Configuration Guide. - [File Post App](https://knowledge.threatconnect.com/docs/file-post-app.md): The File Post App is a utility that passes a binary to a Playbook for analysis, the results of which can be passed back to the App. This article describes how to configure and use the File Post App. - [TC Exchange App Development - Install Configuration File User Guide](https://knowledge.threatconnect.com/docs/tc-exchange-app-development-install-configuration-file-user-guide.md): This article provides a PDF file of the TC Exchange App Development - Install Configuration File User Guide for ThreatConnect. - [Indicator Migration App Configuration Guide](https://knowledge.threatconnect.com/docs/indicator-migration-app-configuration-guide.md): This article provides a PDF file of the Indicator Migration App Configuration Guide for ThreatConnect. - [ThreatConnect Indicator CSV Integration Installation and Configuration Guide](https://knowledge.threatconnect.com/docs/threatconnect-indicator-csv-integration-installation-and-configuration-guide.md): This article provides a PDF file of the ThreatConnect Indicator CSV Integration Installation and Configuration Guide. - [Qualys Vulnerability Management Integration Configuration Guide](https://knowledge.threatconnect.com/docs/qualys-vulnerability-management-integration-configuration-guide.md): Configure the Polarity Qualys integration: API key setup, authentication flow, endpoint URLs, and troubleshooting common Qualys API errors. - [Tenable.sc Integration Configuration Guide](https://knowledge.threatconnect.com/docs/tenablesc-integration-configuration-guide.md): This article provides a PDF file of the Tenable.sc Integration Configuration Guide for ThreatConnect. - [Contributing a Group to a Community or Source](https://knowledge.threatconnect.com/docs/contributing-a-group-to-a-community-or-source.md): This article describes how to contribute a Group to a Community or Source, view the properties of a contributed Group, and recontribute a Group. - [Group Hierarchy and Association Directionality](https://knowledge.threatconnect.com/docs/group-hierarchy-and-association-directionality.md): This article provides an overview of how Groups are related to each other in ThreatConnect and the association directionality that occurs when you contribute a Group to a Community or Source. - [Copying a Group From a Community or Source](https://knowledge.threatconnect.com/docs/copying-a-group-from-a-community-or-source.md): This article describes how to copy a Group from a Community or Source to an Organization in ThreatConnect. - [Posts](https://knowledge.threatconnect.com/docs/posts.md): This article describes the functionality of posts in ThreatConnect, including how to view, create, reply to, and delete posts and link posts to threat intelligence objects. - [The Cross-Intel Sharing App: Sharing Data Across ThreatConnect Instances](https://knowledge.threatconnect.com/docs/the-cross-intel-sharing-app-sharing-data-across-threatconnect-instances.md): The Cross-Intel Sharing App allows you to share packaged intelligence in the form of Group objects with other ThreatConnect instances. This article describes how Org Admins can install, configure, and run the App in the receiving instance. - [The Publish Feature](https://knowledge.threatconnect.com/docs/the-publish-feature.md): This article describes how to publish a Group in a JSON file so that you may share it with users on other instances of ThreatConnect via the Cross-Intel Sharing App. - [Content Packs Overview](https://knowledge.threatconnect.com/docs/content-packs-overview.md): This article provides an overview of Content Packs in ThreatConnect and the corresponding minimum roles and prerequisites for this feature. - [Creating Content Packs](https://knowledge.threatconnect.com/docs/creating-content-packs.md): This article describes how to create Content Packs in ThreatConnect using the internal Content Pack API endpoint. - [Installing and Configuring Content Packs](https://knowledge.threatconnect.com/docs/installing-and-configuring-content-packs.md): This article describes the different ways to install a Content Pack in ThreatConnect. It also outlines procedures for configuring the items installed on your ThreatConnect instance as part of the Content Pack installation process. - [Publishing Content Packs](https://knowledge.threatconnect.com/docs/publishing-content-packs.md): This article describes how System Administrators on ThreatConnect Cloud can install a Content Pack and then publish it to the TC Exchange catalog. It also provides best practices to follow before publishing a Content Pack. - [Updating Content Packs](https://knowledge.threatconnect.com/docs/updating-content-packs.md): This article describes how to update a Content Pack installed on your ThreatConnect instance. - [Content Packs FAQ and Known Issues](https://knowledge.threatconnect.com/docs/content-packs-faq-and-known-issues.md): This article provides a list of frequently asked questions (FAQ) and known issues related to Content Packs in ThreatConnect. - [Microsoft Sentinel Content Pack Overview](https://knowledge.threatconnect.com/docs/microsoft-sentinel-content-pack-overview.md): This article provides an overview of the Microsoft Sentinel Content Pack in ThreatConnect, the corresponding minimum roles and prerequisites needed to use it, and additional Microsoft Sentinel resources. - [Installing and Configuring the Microsoft Sentinel Content Pack](https://knowledge.threatconnect.com/docs/installing-and-configuring-the-microsoft-sentinel-content-pack.md): This article describes how to install the Microsoft Sentinel Content Pack via TC Exchange and the configuration you must complete in ThreatConnect and Microsoft Sentinel to use the Content Pack. - [Microsoft Sentinel Content Pack Use Cases](https://knowledge.threatconnect.com/docs/microsoft-sentinel-content-pack-use-cases.md): This article describes the use cases supported by the Microsoft Sentinel Content Pack in ThreatConnect. - [Microsoft Sentinel Content Pack Data Mappings](https://knowledge.threatconnect.com/docs/microsoft-sentinel-content-pack-data-mappings.md): This article provides data mappings for data created in ThreatConnect from incidents, alerts, and entities in Microsoft Sentinel. These data mappings apply to the Microsoft Sentinel Content Pack. - [ReversingLabs A1000 Content Pack Overview](https://knowledge.threatconnect.com/docs/reversinglabs-a1000-content-pack-overview.md): This article provides an overview of the ReversingLabs A1000 Content Pack in ThreatConnect, the corresponding minimum roles and prerequisites needed to use it, and additional ReversingLabs A1000 resources. - [Installing and Configuring the ReversingLabs A1000 Content Pack](https://knowledge.threatconnect.com/docs/installing-and-configuring-the-reversinglabs-a1000-content-pack.md): This article describes how to install the ReversingLabs A1000 Content Pack via TC Exchange and the configuration you must complete in ThreatConnect to use the Content Pack. - [ReversingLabs A1000 Content Pack Use Cases](https://knowledge.threatconnect.com/docs/reversinglabs-a1000-content-pack-use-cases.md): This article describes the use cases supported by the ReversingLabs A1000 Content Pack in ThreatConnect. - [Zscaler Internet Access Content Pack Overview](https://knowledge.threatconnect.com/docs/zscaler-internet-access-content-pack-overview.md): This article provides an overview of the Zscaler Internet Access Content Pack in ThreatConnect, the corresponding minimum roles and prerequisites needed to use it, and additional Zscaler resources. - [Installing and Configuring the Zscaler Internet Access Content Pack](https://knowledge.threatconnect.com/docs/installing-and-configuring-the-zscaler-internet-access-content-pack.md): This article describes how to install the Zscaler Internet Access Content Pack via TC Exchange and the configuration you must complete in ThreatConnect to use the Content Pack. - [Zscaler Internet Access Content Pack Use Cases](https://knowledge.threatconnect.com/docs/zscaler-internet-access-content-pack-use-cases.md): This article describes the use cases supported by the Zscaler Internet Access Content Pack in ThreatConnect. - [The Playbooks Screen](https://knowledge.threatconnect.com/docs/the-playbooks-screen.md): This article describes the functionalities available on the Playbooks screen, which lists all Playbooks, including Playbook Components and Workflow Playbooks, available in your Organization. - [The Playbook Designer Overview](https://knowledge.threatconnect.com/docs/the-playbook-designer-overview.md): This article provides an overview of the Playbook Designer screen in ThreatConnect and the corresponding minimum roles and prerequisites for this feature. - [The Playbook Designer Screen Overview](https://knowledge.threatconnect.com/docs/the-playbook-designer-screen-overview.md): This article provides an overview of the Playbook Designer screen, highlighting the main parts of the screen as it appears when a new Playbook is created. - [Mode](https://knowledge.threatconnect.com/docs/mode.md): This article describes the modes available on the Playbook Designer screen: Design Mode: Interactive Mode, and Active. - [Administration and Settings Overview](https://knowledge.threatconnect.com/docs/administration-and-settings-overview.md): This article provides an overview of the administration and settings options available on the Playbook Designer screen and describes where to find the menus providing these options. - [Administration Options](https://knowledge.threatconnect.com/docs/administration-options.md): This article describes the administration options available via the vertical ellipsis menu at the upper-right corner of the Playbook Designer. - [Settings](https://knowledge.threatconnect.com/docs/settings.md): This article describes the options available via the Settings menu in the upper-right corner of the Playbook Designer. - [Tabbed Layout](https://knowledge.threatconnect.com/docs/tabbed-layout.md): This article describes the tabbed layout of the Playbook Designer, which displays features of an open Playbook in individual tabs. - [Side Navigation Bar Overview](https://knowledge.threatconnect.com/docs/side-navigation-bar-overview.md): This article provides an overview of the side navigation bar in the Playbook Designer, showing the bar with icons and labels as well as collapsed. - [Summary](https://knowledge.threatconnect.com/docs/summary.md): This article describes the Summary option on the side navigation bar of the Playbook Designer. - [Validations](https://knowledge.threatconnect.com/docs/validations.md): This article describes the Validations option on the side navigation bar of the Playbook Designer. - [Triggers](https://knowledge.threatconnect.com/docs/triggers-1.md): This article describes the Triggers option on the side navigation bar of the Playbook Designer. - [Apps](https://knowledge.threatconnect.com/docs/apps.md): This article describes the Apps option on the side navigation bar of the Playbook Designer. - [Operators](https://knowledge.threatconnect.com/docs/operators.md): This article describes the Operators option on the side navigation bar of the Playbook Designer. - [Executions](https://knowledge.threatconnect.com/docs/executions.md): This article describes the Executions option on the side navigation bar of the Playbook Designer. - [Run Profiles](https://knowledge.threatconnect.com/docs/run-profiles.md): This article describes the Run Profiles option on the side navigation bar of the Playbook Designer. - [Metadata (Global Variables)](https://knowledge.threatconnect.com/docs/metadata-global-variables.md): This article describes the Metadata option on the side navigation bar of the Playbook Designer. - [Versions](https://knowledge.threatconnect.com/docs/versions.md): This article describes the Versions option on the side navigation bar of the Playbook Designer. - [Components](https://knowledge.threatconnect.com/docs/components.md): This article describes the Components option on the side navigation bar of the Playbook Designer. - [DataStore](https://knowledge.threatconnect.com/docs/datastore.md): This article describes the DataStore option on the side navigation bar of the Playbook Designer. - [Audit Log](https://knowledge.threatconnect.com/docs/audit-log.md): This article describes the Audit Log option on the side navigation bar of the Playbook Designer. - [Adding and Configuring Playbook Elements Overview](https://knowledge.threatconnect.com/docs/adding-and-configuring-playbook-elements-overview.md): This article provides an overview of how to add and configure Playbook elements in the Playbook Designer. - [Adding a Trigger](https://knowledge.threatconnect.com/docs/adding-a-trigger.md): This article describes how to add Triggers in the Playbook Designer. - [Adding an App](https://knowledge.threatconnect.com/docs/adding-an-app.md): This article describes how to add Apps in the Playbook Designer. - [Adding an Operator](https://knowledge.threatconnect.com/docs/adding-an-operator.md): This article describes how to add Operators in the Playbook Designer. - [Connecting Playbook Elements](https://knowledge.threatconnect.com/docs/connecting-playbook-elements.md): This article provides a brief description of how to connect Playbook elements in the Playbook Designer. - [Formatting a Playbook](https://knowledge.threatconnect.com/docs/formatting-a-playbook.md): This article describe how to use the zoom, layout, group selection, and administrative icons in the Playbook Designer. - [Activating a Playbook](https://knowledge.threatconnect.com/docs/activating-a-playbook.md): This article describes how to activate a Playbook, including an explanation of the Mode dropdown and how to deal with validation errors. - [Interactive Playbooks Overview](https://knowledge.threatconnect.com/docs/interactive-playbooks-overview.md): This article provides an overview of how to use Interactive Mode in the Playbook Designer - [Design Pane (Interactive Mode)](https://knowledge.threatconnect.com/docs/design-pane-interactive-mode.md): This article describes how to execute Playbook elements in Interactive Mode in the Playbook Designer. - [Variable Explorer](https://knowledge.threatconnect.com/docs/variable-explorer.md): This article describes the Variable Explorer tab in Interactive Mode in the Playbook Designer. - [Execution Details](https://knowledge.threatconnect.com/docs/execution-details.md): This article describes the Execution Details tab in Interactive Mode in the Playbook Designer. - [Notes](https://knowledge.threatconnect.com/docs/notes-1.md): This article describes the Notes tab in Interactive Mode in the Playbook Designer. - [The Playbook Designer Keyboard Shortcuts](https://knowledge.threatconnect.com/docs/the-playbook-designer-keyboard-shortcuts.md): This article provides a list of keyboard and mousewheel shortcuts that can be used when designing a Playbook in the Playbook Designer. - [Parts of a Playbook](https://knowledge.threatconnect.com/docs/parts-of-a-playbook.md): This article describes each Trigger, App, and Operator type (the main building blocks of Playbooks in ThreatConnect) and provides links to articles that contain more detailed information. - [The Mailbox Trigger](https://knowledge.threatconnect.com/docs/playbooks-the-mailbox-trigger.md): This article describes how to configure the Mailbox Trigger, which allows you to create a mailbox to send information to a Playbook in ThreatConnect. - [The Timer Trigger](https://knowledge.threatconnect.com/docs/playbooks-the-timer-trigger.md): This article describes how to configure the Timer Trigger, which allows you to trigger a ThreatConnect Playbook on a set schedule. - [The UserAction Trigger](https://knowledge.threatconnect.com/docs/the-useraction-trigger.md): This article describes how to configure the UserAction Trigger, which lets you run Playbooks on demand while viewing details for Groups, Indicators, Intelligence Requirements, Tracks, and Victims in Requirements, and Victims in ThreatConnect. - [The WebHook Trigger](https://knowledge.threatconnect.com/docs/the-webhook-trigger.md): This article describes how to configure the WebHook Trigger in a ThreatConnect Playbook. This Trigger creates an HTTPS endpoint that can process nearly any piece of information that can be sent via HTTP. - [Playbooks Iterator Operator](https://knowledge.threatconnect.com/docs/playbooks-iterator-operator.md): The Iterator Operator iterates through items in an input array or set of arrays, applies Playbook logic to each item, and returns the output to the Playbook. This article describes how to configure and use the Iterator and Break Iterator Operator. - [HTTP Client - Configuring HTTP Requests in cURL Format](https://knowledge.threatconnect.com/docs/http-client-configuring-http-requests-in-curl-format.md): This article provides sample HTTP requests that use cURL and demonstrates how to configure each request in the HTTP Client Playbook App. - [Playbook Components Overview](https://knowledge.threatconnect.com/docs/playbook-components-overview.md): This article provides an overview of Playbook Components in ThreatConnect and the corresponding minimum roles and prerequisites for this feature. - [Creating a Component](https://knowledge.threatconnect.com/docs/creating-a-component.md): This article describes how to create and configure a Playbook Component in ThreatConnect. - [Editing a Component](https://knowledge.threatconnect.com/docs/editing-a-component.md): This article describes how to edit a Playbook Component in ThreatConnect. - [Administrating a Component](https://knowledge.threatconnect.com/docs/administrating-a-component.md): This article describes how to find administrative options for a Playbook Component in ThreatConnect. - [Using a Component in a Playbook](https://knowledge.threatconnect.com/docs/using-a-component-in-a-playbook.md): This article describes how to add an active Component to a Playbook, as well as how to configure and administrate the Component within the Playbook. - [Cloning a Playbook as a Component](https://knowledge.threatconnect.com/docs/cloning-a-playbook-as-a-component.md): This article describes how to clone a Playbook as a Component in ThreatConnect. - [Executing a Playbook](https://knowledge.threatconnect.com/docs/executing-a-playbook.md): This article describes how to execute Playbooks that use Mailbox, Timer, UserAction, WebHook, Group, Indicator, Case, Track, and Victim Triggers. - [Playbook Executions](https://knowledge.threatconnect.com/docs/playbook-executions.md): This article describes how to view the details and logs for a Playbook execution, view an active Playbook execution in the Execution Graph pane, and stop (or kill) a Playbook execution. - [Playbooks: Run Profiles](https://knowledge.threatconnect.com/docs/playbooks-run-profiles.md): Run Profiles represent the data type or event needed to execute a Playbook without navigating away from the Playbook Designer. This article describes how to view, manage, and create Run Profiles and execute a Playbook using a Run Profile. - [Playbook Versions](https://knowledge.threatconnect.com/docs/playbook-versions.md): This article explains major and minor version numbering in Playbooks, discusses how to view Playbook version history, and describes how to create new major and minor versions of a Playbook or Component. - [Playbook Templates](https://knowledge.threatconnect.com/docs/playbook-templates.md): This article describes how to view, search for, install and delete Playbook Templates. It also describes how to import a Template as a Playbook. - [Playbooks: Return on Investment](https://knowledge.threatconnect.com/docs/playbooks-return-on-investment.md): Playbooks ROI enables you to view and visualize the return on investment for the Playbooks executed in your Organization. This article describes how to configure and view ROI for a Playbook and access ROI dashboard metrics. - [Multi-Environment Orchestration: Executing Playbook Apps Through a Firewall](https://knowledge.threatconnect.com/docs/multi-environment-orchestration-executing-playbook-apps-through-a-firewall.md): This article describes how to configure remote execution for Playbook Apps and Service Triggers in ThreatConnect. - [Playbook Environments Overview](https://knowledge.threatconnect.com/docs/playbook-environments-overview.md): This article provides an overview of Playbook Environments in ThreatConnect and the corresponding minimum roles and prerequisites for this feature. - [Viewing, Activating, and Managing Playbook Environments](https://knowledge.threatconnect.com/docs/viewing-activating-and-managing-playbook-environments.md): This article describes how to view, activate, and manage Playbook Environments on the Environments screen in ThreatConnect. - [Administrating an Environment](https://knowledge.threatconnect.com/docs/administrating-an-environment.md): This article describes the actions you can perform on an Environment’s administration screen, including how to view details about the Environment and change aspects of its configuration. - [Playbook Activity](https://knowledge.threatconnect.com/docs/playbook-activity.md): This article discusses functionality available on the Playbooks Activity screen, which is a control panel on which Organization Administrators can monitor Playbook Server and Worker execution metrics, priorities, and processes. - [Playbook Services](https://knowledge.threatconnect.com/docs/playbook-services.md): This article describes the function of Playbook Services Apps, which are microservices that constantly run in the background. It also describes how to create, view, and use Services. - [Playbooks Glossary](https://knowledge.threatconnect.com/docs/playbooks-glossary.md): This glossary consists of the terminology used within ThreatConnect’s Playbooks feature and its various screens. For a complete list of Playbook Apps available in ThreatConnect, visit the ThreatConnect Marketplace. - [Adding App Profiles](https://knowledge.threatconnect.com/docs/adding-app-profiles.md): An App profile in ThreatConnect serves as a proxy for an App, and users interact directly with the profiled version of the installed App. This article describes how Organization Administrators can create an App profile in their Organization. - [Creating a Phishing Mailbox](https://knowledge.threatconnect.com/docs/creating-a-phishing-mailbox.md): This article describes how to create and configure a phishing mailbox in ThreatConnect. - [Creating an HTTP Feed](https://knowledge.threatconnect.com/docs/creating-an-http-feed.md): This article describes how to create an HTTP feed for sources of information in ThreatConnect. - [Creating Custom Attribute Types](https://knowledge.threatconnect.com/docs/creating-custom-attribute-types.md): This article describes how Organization Administrators can create and configure custom Attributes Types in ThreatConnect. - [Creating Indicator Exclusion Lists](https://knowledge.threatconnect.com/docs/creating-indicator-exclusion-lists.md): This article describes how to create, view, and manage Organization-level Indicator Exclusion Lists, which prevent the import of Indicators that may be deemed legitimate or non-hostile. It also describes how to add an Indicator to an Exclusion List. - [Creating Jobs Using TC Exchange Apps](https://knowledge.threatconnect.com/docs/creating-jobs-using-tc-exchange-apps.md): ThreatConnect can integrate with many third-party applications and services. This article demonstrates how to create a Job in ThreatConnect using these product integrations as Apps via TC Exchange. - [Custom Security Labels](https://knowledge.threatconnect.com/docs/custom-security-labels.md): This article describes how to create Organization-wide Security Labels. - [Feed API Services](https://knowledge.threatconnect.com/docs/feed-api-services.md): This article describes how to install Feed API Service Apps via TC Exchange and activate and edit their corresponding Service on the Services tab of the Playbooks screen. - [Handling Incoming Emails](https://knowledge.threatconnect.com/docs/handling-incoming-emails.md): This article describes important configurations and settings for email ingestion in ThreatConnect. - [System Indicator Confidence Deprecation](https://knowledge.threatconnect.com/docs/system-indicator-confidence-deprecation.md): This article describes how to view, create, and configure System Indicator confidence deprecation rules. - [Organization Indicator Confidence Deprecation](https://knowledge.threatconnect.com/docs/organization-indicator-confidence-deprecation.md): This article describes how to view, create, and configure Organization Indicator confidence deprecation rules. - [Community and Source Indicator Confidence Deprecation](https://knowledge.threatconnect.com/docs/community-and-source-indicator-confidence-deprecation.md): This article describes how to view, create, and configure Community and Source Indicator confidence deprecation rules. - [Managing User Accounts](https://knowledge.threatconnect.com/docs/managing-user-accounts.md): This article describes how to create, edit, and delete API, TAXII, standard, and Read Only user accounts in ThreatConnect. - [My Profile](https://knowledge.threatconnect.com/docs/my-profile.md): This article explains the functionalities available on all of the tabs of the My Profile screen in ThreatConnect. - [Notifications and Following](https://knowledge.threatconnect.com/docs/notifications-and-following.md): This article demonstrates the functionality of the Notifications Center in ThreatConnect and explains the available settings for following objects in ThreatConnect, including push notifications and email updates. - [The Feed Deployer](https://knowledge.threatconnect.com/docs/the-feed-deployer.md): This article describes how to use the Feed Deployer in ThreatConnect. Apps with feeds take advantage of the feed-deployment mechanism to create Sources, which then run associated Jobs. - [ThreatConnect Environment Server Installation Guide](https://knowledge.threatconnect.com/docs/threatconnect-environment-server-installation-guide.md): This article describes how to install and configure an Environment Server in ThreatConnect. It also provides the system and network traffic port requirements that must be met in order to install an Environment Server. - [ThreatConnect TAXII Ingest User Guide](https://knowledge.threatconnect.com/docs/threatconnect-taxii-ingest-user-guide.md): This article is a user guide for the ThreatConnect TAXII Ingest App. - [STIX 2.1 Parser Job App Data Mappings](https://knowledge.threatconnect.com/docs/stix-21-parser-job-app-data-mappings.md): This article provides data mappings for data created in ThreatConnect from a Structured Threat Information eXpression (STIX) file parsed using the STIX 2.1 Parser Job App. - [STIX and CybOX Parser Data Mappings](https://knowledge.threatconnect.com/docs/stix-and-cybox-parser-data-mappings.md): The Structured Threat Information eXpression (STIX) and CybOX parser data mappings provided in this article apply to the STIX 1.1.1 parser when configuring an inbound TAXII feed, as well as to the STIX Parser Playbook app in ThreatConnect. - [Creating an Inbound TAXII Exchange Feed](https://knowledge.threatconnect.com/docs/creating-an-inbound-taxii-exchange-feed.md): This article describes how to set up an Inbound TAXII Exchange Feed in ThreatConnect. - [Creating an Outbound TAXII Exchange Feed](https://knowledge.threatconnect.com/docs/creating-an-outbound-taxii-exchange-feed.md): This article describes how to set up an Outbound TAXII Exchange Feed in ThreatConnect. - [Installing and Configuring the ThreatConnect TAXII 2.1 Server (App Version 2.0)](https://knowledge.threatconnect.com/docs/installing-and-configuring-the-threatconnect-taxii-21-server.md): This article describes how to install and configure version 2.0 of the ThreatConnect TAXII Server Service App for use in conjunction with the ThreatConnect TAXII 2.1 server, as well as how to use the ThreatConnect TAXII Server user interface. - [Creating a TAXII User for the ThreatConnect TAXII 2.1 Server (App Version 2.0)](https://knowledge.threatconnect.com/docs/creating-a-taxii-user-for-the-threatconnect-taxii-21-server.md): This article describes how Organization Administrators can create a TAXII user account and configure it to use the ThreatConnect TAXII 2.1 server. - [Retrieving Data From the ThreatConnect TAXII 2.1 Server (App Version 2.0)](https://knowledge.threatconnect.com/docs/retrieving-data-from-the-threatconnect-taxii-21-server.md): This article provides an overview of how TAXII users can use the TAXII REST API to retrieve data from the ThreatConnect TAXII 2.1 server. - [TAXII 2.1 Server Overview (App Version 1.0)](https://knowledge.threatconnect.com/docs/taxii-21-server-overview.md): This article provides an overview of the TAXII 2.1 server in ThreatConnect and the corresponding minimum roles and prerequisites for this feature. - [Installing and Configuring the TAXII 2.1 Server Service (App Version 1.0)](https://knowledge.threatconnect.com/docs/installing-and-configuring-the-taxii-21-server-service.md): This article describes how to install and configure the ThreatConnect TAXII Server Service App for use in conjunction with the ThreatConnect TAXII 2.1 server. - [Creating a TAXII User for the TAXII 2.1 Server (App Version 1.0)](https://knowledge.threatconnect.com/docs/creating-a-taxii-user-for-the-taxii-21-server.md): This article describes how Organization Administrators can create a TAXII user account and configure it to use the TAXII 2.1 server. - [Retrieving Data from the TAXII 2.1 Server (App Version 1.0)](https://knowledge.threatconnect.com/docs/retrieving-data-from-the-taxii-21-server.md): This article provides an overview of how TAXII users can use the TAXII REST API to retrieve data from the TAXII 2.1 server. - [Using the ThreatConnect TAXII Server](https://knowledge.threatconnect.com/docs/using-the-threatconnect-taxii-server.md): This article describes how to create a TAXII user account and configure it to use the TAXII 1.x server. - [Workflow Overview](https://knowledge.threatconnect.com/docs/workflow-overview.md): This article provides a high-level overview of Workflow, covering terminology and process flow. It links to separate articles that cover each element of the Workflow process in detail. - [Parts of a Case](https://knowledge.threatconnect.com/docs/parts-of-a-case.md): This article describes how to view and manage a Case, as well as the various components and elements included in a Case. When applicable, links to articles with more detailed information about these Case components and elements will be provided. - [The Cases Screen Overview](https://knowledge.threatconnect.com/docs/the-cases-screen-overview.md): This article provides an overview of the Cases tab of the Workflow screen in ThreatConnect and the corresponding minimum roles and prerequisites for features on this screen. - [Viewing, Managing, and Filtering Cases](https://knowledge.threatconnect.com/docs/viewing-managing-and-filtering-cases.md): This article describes how to view, manage, and filter Workflow Cases on the Cases screen in ThreatConnect. - [Creating Cases](https://knowledge.threatconnect.com/docs/creating-cases.md): This article describes how to create a Case using a Workflow and without using a Workflow. - [Artifacts Overview](https://knowledge.threatconnect.com/docs/artifacts-overview.md): This article provides an overview of Artifacts in ThreatConnect and the corresponding minimum roles and prerequisites for this feature. - [Artifacts Card](https://knowledge.threatconnect.com/docs/artifacts-card.md): This article describes each table column in a Workflow Case's Artifacts card and how to sort and filter Artifacts displayed in the table. - [Adding Artifacts to a Case](https://knowledge.threatconnect.com/docs/adding-artifacts-to-a-case.md): This article describes how to add Artifacts to a Workflow Case. - [Artifact Administrative Options](https://knowledge.threatconnect.com/docs/artifact-administrative-options.md): This article describes the administrative options available when you click the vertical ellipsis in the rightmost column of the table on the Artifacts card of a Workflow Case. - [Viewing Artifact Details](https://knowledge.threatconnect.com/docs/viewing-artifact-details.md): This article describes how to view the following details about an Artifact added to a Workflow Case: summary, CAL score, enrichment data, associated Indicators and Groups, potentially associated Indicators and Groups, and Notes. - [Case Attributes](https://knowledge.threatconnect.com/docs/case-attributes.md): This article describes how to add Attributes to a Case, edit existing Attributes added to a Case, and remove Attributes from a Case. - [Case Associations Overview](https://knowledge.threatconnect.com/docs/case-associations-overview.md): This article provides an overview of a Workflow Case's Associations and Potential Associations cards. It also provides the minimum roles and prerequisites for Case associations. - [Associations Card for Cases](https://knowledge.threatconnect.com/docs/associations-card-for-cases.md): This article describes how to view Indicators, Groups, and Cases associated to a Workflow Case and add associations via the Case’s Associations card. - [Potential Associations Card for Cases](https://knowledge.threatconnect.com/docs/potential-associations-card-for-cases.md): This article describes how to view Indicators, Groups, and Cases potentially associated to a Workflow Case via the Case's Potential Associations card, associate these objects to the Case, and perform bulk actions on potentially associated Cases. - [Case Details](https://knowledge.threatconnect.com/docs/case-details.md): This article describes the elements included in the Case Details card of a Workflow Case and provides instructions on how to update each element. - [Case Notes](https://knowledge.threatconnect.com/docs/case-notes.md): This article describes how to add Notes to a Workflow Case, manage existing Notes, and link Notes to a Task or Artifact in a Case. - [Phases and Tasks Overview](https://knowledge.threatconnect.com/docs/phases-and-tasks-overview.md): This article provides an overview of a Workflow Case's Phases and Tasks section. It also provides the minimum rules and prerequisites that correspond to this feature. - [Phases and Tasks Section](https://knowledge.threatconnect.com/docs/phases-and-tasks-section.md): This article describes how to view the Phases and Tasks in a Case. It also describes the types of Tasks that you can add to a Case and the various Task elements, including its assignee, dependency, and due date. - [Adding Tasks to a Case](https://knowledge.threatconnect.com/docs/adding-tasks-to-a-case.md): This article describes how to add a manual and automated Task to a Workflow Case and configure a Task's Artifact Fields. - [Viewing and Filtering Tasks in a Case](https://knowledge.threatconnect.com/docs/viewing-and-filtering-tasks-in-a-case.md): This article describes how to view and filter Tasks in a Workflow Case's Phases and Tasks section. - [Task Administrative Options](https://knowledge.threatconnect.com/docs/task-administrative-options.md): This article describes the Task administrative options you can perform when the Phases and Tasks section of a Workflow Case is displayed in detail and list view. - [Timeline Events](https://knowledge.threatconnect.com/docs/timeline-events.md): This article describes how to view and filter a Case's Timeline Events and add a Timeline Event to a Case manually. - [The Details Drawer for Workflow Cases](https://knowledge.threatconnect.com/docs/the-details-drawer-for-workflow-cases.md): This article describes the Details drawer for Workflow Cases and provides information on the actions you can perform from this drawer. - [Managing Service Level Agreements for Workflow Cases](https://knowledge.threatconnect.com/docs/managing-service-level-agreements-for-workflow-cases.md) - [Workflow Playbooks Overview](https://knowledge.threatconnect.com/docs/workflow-playbooks-overview.md): This article provides an overview of Workflow Playbooks in ThreatConnect and the corresponding minimum roles and prerequisites for this feature. - [Creating a Workflow Playbook](https://knowledge.threatconnect.com/docs/creating-a-workflow-playbook.md): This article describes how to create a Workflow Playbook and configure its Workflow Trigger. - [Cloning a Playbook as a Workflow Playbook](https://knowledge.threatconnect.com/docs/cloning-a-playbook-as-a-workflow-playbook.md): This article describes how to clone an existing Playbook as a Workflow Playbook. - [Workflow Tasks](https://knowledge.threatconnect.com/docs/workflow-tasks.md): This article provides instruction on the features of the Tasks tab of the Workflow screen in ThreatConnect, covering viewing, assigning, removing, sorting, and filtering Tasks. - [Workflows and Workflow Templates Overview](https://knowledge.threatconnect.com/docs/workflows-and-workflow-templates-overview.md): This article provides an overview of Workflows and Workflow Templates in ThreatConnect and the corresponding minimum roles and prerequisites for each feature. - [The Workflows Screen](https://knowledge.threatconnect.com/docs/the-workflows-screen.md): This article describes the Workflows tab of the Workflow screen in ThreatConnect and the actions you can perform on this screen. - [The Templates Screen](https://knowledge.threatconnect.com/docs/the-templates-screen.md): This article describes the Templates tab of the Workflow screen in ThreatConnect and the actions you can perform on this screen. - [Building and Activating a Workflow](https://knowledge.threatconnect.com/docs/building-and-activating-a-workflow.md): This article describes the process of building a Workflow, including how to add Attributes and Tasks to a Workflow. It also describes how to activate Workflow so that it can be used when creating a Case. - [How Polarity Works](https://knowledge.threatconnect.com/docs/how-pie-works.md): Learn how Polarity Intel Edition (PIE) works for threat intelligence teams. Discover real-time threat annotation, auto-detection of IOCs, live highlighting, and team collaboration features for security analysts. - [macOS Settings for the Polarity Intel Edition Client](https://knowledge.threatconnect.com/docs/macos-settings-for-the-pie-client.md): Configure Polarity Intel Edition client settings on macOS. Learn how to customize application preferences, network settings, and threat-intelligence feeds for your Mac deployment. - [Polarity Overlay Window](https://knowledge.threatconnect.com/docs/polarity-overlay-window-2.md): Learn how Polarity Intel Edition's overlay window auto-detects and highlights threats in real-time as you browse. Discover how the browser extension displays live annotations, indicators, and threat intelligence inline without leaving your webpage. - [Recognition Modes](https://knowledge.threatconnect.com/docs/recognition-modes-2.md): Configure recognition modes in Polarity Intel Edition to enable real-time highlighting and automatic detection of threat intelligence indicators. Learn how to activate live annotation and entity recognition for faster threat identification. - [Entities in Polarity](https://knowledge.threatconnect.com/docs/entities-in-pie.md): Learn about entities in Polarity Intel Edition—the threat intelligence observables and indicators of compromise (IOCs) that the platform auto-detects, tags, and annotates. Discover entity types, recognition methods, and how to work with detected data. - [Polarity Integrations](https://knowledge.threatconnect.com/docs/polarity-integrations-3.md): Polarity Intel Edition integrations connect your threat intelligence platform to external data sources, plugins, and third-party tools. Learn which connectors are available, how to configure data source connections, and how to extend Polarity's annotation capabilities with custom integrations. - [Advanced Settings](https://knowledge.threatconnect.com/docs/advanced-settings-2.md): Configure advanced options in Polarity Intel Edition to customize performance, security, and threat-intelligence processing. Learn how to tune detection settings, manage real-time highlighting, adjust integration behavior, and optimize your threat-intel workflow. - [My Profile](https://knowledge.threatconnect.com/docs/my-profile-1-2.md): Learn to manage your Polarity Intel Edition user profile, configure personal preferences, update account information, and customize your client settings for threat intelligence annotation and collaboration. - [Polarity Browser Extension](https://knowledge.threatconnect.com/docs/polarity-browser-extension-2.md): Install and use the Polarity Intel Edition browser extension to automatically detect and annotate threat indicators while searching the web. Get real-time highlights, live alerts, and security intelligence directly in your browser with this lightweight threat-intel plugin. - [Shortcut Keys](https://knowledge.threatconnect.com/docs/shortcut-keys-2.md): Learn keyboard shortcuts and hotkeys in Polarity Intel Edition to speed up threat intelligence annotation, navigation, and analysis. Discover quick keys for tagging, searching, and workflow acceleration. - [Reporting Issues](https://knowledge.threatconnect.com/docs/reporting-issues-2.md): Learn how to report bugs and technical issues in Polarity Intel Edition. Find step-by-step instructions for submitting support tickets, documenting problems, and getting help from the Polarity team. - [How Polarity Works](https://knowledge.threatconnect.com/docs/how-polarity-works.md): Learn how Polarity Enterprise helps security teams annotate, tag, and share threat intelligence across shared channels. Discover core features including real-time highlighting, team collaboration, and integration workflows. - [macOS Settings for the Polarity Enterprise Client](https://knowledge.threatconnect.com/docs/macos-settings-for-the-polarity-enterprise-client.md): Configure Polarity Enterprise Client on macOS with step-by-step settings instructions. Learn how to install, configure preferences, and optimize the annotation client for Mac systems in enterprise deployments. - [Polarity Overlay Window](https://knowledge.threatconnect.com/docs/polarity-overlay-window.md): Learn how Polarity Enterprise's overlay window displays live annotations, tags, and highlights directly on web pages. Understand how to view, interact with, and manage real-time threat intelligence markup in your browser. - [Recognition Modes](https://knowledge.threatconnect.com/docs/recognition-modes.md): Learn how Polarity Enterprise's recognition modes enable real-time highlighting and auto-detection of entities across your browser. Configure live annotation, entity recognition settings, and auto-tagging behavior to streamline threat intelligence workflows. - [Entities and Annotations](https://knowledge.threatconnect.com/docs/entities-and-annotations.md): Learn how to tag and label entities in Polarity Enterprise. Discover how to create, manage, and apply annotations to mark up data, highlight key information, and collaborate on entity recognition across your team. - [Polarity Integrations](https://knowledge.threatconnect.com/docs/polarity-integrations.md): Learn how to configure and use Polarity Enterprise integrations to connect third-party data sources, threat-intelligence feeds, and external tools. Discover available plugins and connectors to extend Polarity's annotation and enrichment capabilities. - [Annotation Channels](https://knowledge.threatconnect.com/docs/annotation-channels.md): Learn how to create and manage annotation channels in Polarity Enterprise—shared team workspaces where you can organize collaborative annotations, tags, and notes. Set up channels for different projects, teams, or data sources to streamline group annotation workflows. - [Advanced Settings](https://knowledge.threatconnect.com/docs/advanced-settings.md): Configure advanced client settings in Polarity Enterprise to customize annotation behavior, performance, and integrations. Access system preferences and tune recognition, display, and data handling options for your workflow. - [My Profile](https://knowledge.threatconnect.com/docs/my-profile-1.md): Configure your personal profile and account settings in Polarity Enterprise. Learn how to update your preferences, manage notification settings, and customize your client experience. - [Team Management](https://knowledge.threatconnect.com/docs/team-management.md): Manage Polarity team members and user roles. View current license status, active seat count, and subscription details under the License Information section. - [Tasks](https://knowledge.threatconnect.com/docs/tasks.md): Configure and manage tasks in Polarity Enterprise to automate workflows and assign work to team members. Learn how to set up task management, create assignments, and track project work within your annotation platform. - [Server Configuration](https://knowledge.threatconnect.com/docs/server-configuration.md): Configure your Polarity Enterprise server deployment with admin settings. Learn how to set up environment variables, Docker/Podman containers, and system parameters for your annotation platform. - [Explore Page](https://knowledge.threatconnect.com/docs/explore-page.md): The Polarity Enterprise Explore Page lets you search, filter, and browse all annotations and tagged entities across your workspace. Discover threat intelligence, find team notes, and locate specific tags or labels added by collaborators. - [Channel and Integration Permissions](https://knowledge.threatconnect.com/docs/channel-and-integration-permissions.md): Learn how to manage channel and integration permissions in Polarity Enterprise. Control who can access shared annotation workspaces, connectors, plugins, and data sources using role-based access controls for team collaboration. - [Shortcut Keys](https://knowledge.threatconnect.com/docs/shortcut-keys.md): Master Polarity Enterprise shortcut keys to navigate, annotate, and search faster. Learn keyboard hotkeys for quick tagging, workspace switching, and common platform actions. - [Polarity Browser Extension](https://knowledge.threatconnect.com/docs/polarity-browser-extension.md): Learn how to install and use the Polarity browser extension for real-time annotation and auto-detection of security indicators while searching the web. Highlights and tags threats directly in your browser. - [Troubleshooting the Polarity Client](https://knowledge.threatconnect.com/docs/troubleshooting-the-polarity-client.md): Fix common Polarity Enterprise client problems, including installation errors, connectivity issues, and performance problems. Find step-by-step solutions to get your client running smoothly. - [Reporting Issues](https://knowledge.threatconnect.com/docs/reporting-issues.md): Learn how to report bugs, errors, and problems in Polarity Enterprise. Find the support process, escalation procedures, and how to submit detailed issue reports to get help faster. - [How Polarity Works](https://knowledge.threatconnect.com/docs/how-polarityce-works.md): Learn how Polarity Community Edition operates as a free, lightweight annotation platform. Discover how to tag, label, and annotate data, collaborate on notes, and use the core annotation features without enterprise licensing requirements. - [macOS Settings for the Polarity Community Edition Client](https://knowledge.threatconnect.com/docs/macos-settings-for-the-polarity-ce-client.md): Configure and optimize Polarity Community Edition on macOS. Learn system settings, preferences, and setup steps for the desktop client annotation tool on Mac computers. - [Polarity Overlay Window](https://knowledge.threatconnect.com/docs/polarity-overlay-window-1.md): Learn how the Polarity Community Edition overlay window displays real-time annotations, highlights, and tags as you browse. Discover how auto-detected data is visualized and how to interact with live threat intelligence annotations in your browser. - [Searching On-Demand](https://knowledge.threatconnect.com/docs/search-on-demand.md): Learn how to perform manual searches and execute ad-hoc queries in Polarity Community Edition. Find instructions for real-time threat lookups and executing on-demand searches through the search interface. - [Polarity Integrations](https://knowledge.threatconnect.com/docs/polarity-integrations-1.md): Learn how to connect third-party data sources and plugins to Polarity Community Edition. Discover available integrations, connectors, and APIs to enhance your annotation workflow and threat intelligence capabilities. - [Entities in Polarity](https://knowledge.threatconnect.com/docs/entities-in-polarity.md): Learn how to use entities (tags, labels, and annotations) in Polarity Community Edition to mark up and enrich threat intelligence data. Discover how to create, apply, and manage custom annotations for collaborative threat intelligence work. - [Advanced Settings](https://knowledge.threatconnect.com/docs/advanced-settings-1.md): Configure advanced settings in Polarity Community Edition to customize client behavior, annotation features, and platform preferences. Learn to optimize your workspace configuration and user experience. - [My Profile](https://knowledge.threatconnect.com/docs/my-profile-1-1.md): Configure your personal profile settings in Polarity Community Edition. Access and update your account information, preferences, and user details from the My Profile section in client settings. - [Polarity Browser Extension](https://knowledge.threatconnect.com/docs/polarity-browser-extension-1.md): Polarity Community Edition browser extension auto-detects and highlights indicators during web search in real-time. Learn installation, configuration, and how to use live annotation features while browsing. - [Shortcut Keys](https://knowledge.threatconnect.com/docs/shortcut-keys-1.md): Learn keyboard shortcuts and hotkeys in Polarity Community Edition to speed up annotation, navigation, and tagging. Discover quick commands for efficient threat intelligence workflows. - [Reporting Issues](https://knowledge.threatconnect.com/docs/reporting-issues-1.md): Learn how to report bugs and issues in Polarity Community Edition. Submit detailed error reports, attach logs, and track your support tickets to get help from the community and support team. - [Polarity Server v5 - Administrator's Overview](https://knowledge.threatconnect.com/docs/polarity-administrators-overview.md): Learn how to deploy, configure, and manage Polarity Server v5. This administrator guide covers platform setup, Docker/Podman deployment, user management, channels, integrations, and system monitoring for enterprise annotation teams. - [Fresh Install (Docker)](https://knowledge.threatconnect.com/docs/polarity-server-v5-fresh-install-docker.md): Deploy Polarity Server v5 from scratch using Docker containers. Step-by-step installation guide for administrators setting up the annotation platform on Linux or macOS with Docker Compose. - [Fresh Install (Podman)](https://knowledge.threatconnect.com/docs/polarity-server-v5-fresh-install-podman.md): Step-by-step guide to deploy Polarity Server v5 using Podman as a Docker alternative. Learn container setup, initial configuration, and deployment best practices for a fresh installation. - [Upgrade PostgreSQL Server to v15](https://knowledge.threatconnect.com/docs/polarity-upgrade-postgresql-server-to-v15.md): Learn how to upgrade PostgreSQL Server to v15 for Polarity Server v5 deployment. Step-by-step database migration and configuration guide for administrators upgrading from v4. - [Configure the Server License](https://knowledge.threatconnect.com/docs/polarity-configure-the-server-license.md): Set up and manage your Polarity Server v5 license configuration. Learn how to activate your license, view seat count, check subscription status, and configure license settings for your deployment. - [Configure the Server FQDN](https://knowledge.threatconnect.com/docs/polarity-configure-the-server-fqdn.md): Set up the fully qualified domain name (FQDN) for your Polarity Server v5 deployment. Learn how to configure hostname and domain settings for proper SSL certificates, user access, and network connectivity in your annotation platform. - [Configure the Server SSL Certificates](https://knowledge.threatconnect.com/docs/polarity-configure-server-ssl-certificates.md): Learn how to set up and configure SSL/TLS certificates for Polarity Server v5 to enable HTTPS encryption. Step-by-step guide for administrators deploying secure server instances with proper certificate management and deployment options. - [Configure Proxies](https://knowledge.threatconnect.com/docs/polarity-configuring-proxies.md): Learn how to configure HTTP and HTTPS proxies for Polarity Server v5 to route outbound network connections through your organization's firewall. Step-by-step proxy setup for administrators. - [Configure SMTP](https://knowledge.threatconnect.com/docs/polarity-configuring-smtp.md): Set up SMTP mail server configuration in Polarity Server v5 to enable email notifications and alert delivery. Learn how to configure outbound mail settings, authentication, and test email connectivity for your deployment. - [Configure Azure ADFS as SAML Provider](https://knowledge.threatconnect.com/docs/polarity-configure-azure-adfs.md): Set up Azure ADFS as a SAML identity provider for Polarity Server v5 single sign-on (SSO). Step-by-step configuration guide for enterprise authentication and user access control. - [Configure Okta as SAML Provider](https://knowledge.threatconnect.com/docs/polarity-configure-okta.md): Set up Okta as a SAML identity provider for Polarity Server v5 to enable single sign-on (SSO) and centralized user authentication across your organization. - [SAML Troubleshooting](https://knowledge.threatconnect.com/docs/polarity-saml-troubleshooting.md): Troubleshoot SAML and single sign-on (SSO) authentication issues in Polarity Server v5. Find solutions for identity provider configuration, login errors, and user access problems. - [Configure Command Center AI](https://knowledge.threatconnect.com/docs/configure-command-center-ai.md): Set up and configure Command Center AI for Polarity Server v5. Learn how to enable AI features, customize threat-intelligence settings, and integrate AI capabilities into your annotation platform. - [Server File System Layout](https://knowledge.threatconnect.com/docs/polarity-server-file-system-layout.md): Learn the Polarity Server v5 file system layout and directory structure for Docker or Podman deployment. Understand where configuration files, logs, data, and integration files are stored to properly manage and troubleshoot your server installation. - [Server Environment Variables](https://knowledge.threatconnect.com/docs/polarity-server-environment-variables.md): Configure Polarity Server v5 with environment variables for Docker or Podman deployment. Learn how to set server settings, integrations, and system parameters during installation and runtime. - [Installing Polarity Integrations](https://knowledge.threatconnect.com/docs/polarity-installing-integrations.md): Learn how to install and configure Polarity data source connectors and plugins in Polarity Server v5. Step-by-step guide for administrators to add integrations and connect external data sources to your annotation platform. - [Modifying Integration Names and Acronyms](https://knowledge.threatconnect.com/docs/polarity-modifying-integration-names-and-acronyms.md): Learn how to customize integration and plugin names and acronyms in Polarity Server v5. Configure how data connectors and sources display in your team's annotation workspace. - [Install Multiple Copies of an Integration](https://knowledge.threatconnect.com/docs/polarity-install-multiple-copies-of-an-integration.md): Learn how to deploy multiple instances of the same plugin or connector in Polarity Server v5. Configure separate data sources and integrations with different settings for distributed annotations and threat intelligence workflows. - [Polarity Source Analytics with Splunk](https://knowledge.threatconnect.com/docs/polarity-source-analytics-with-splunk.md): Send Polarity usage metrics and source telemetry to Splunk via PSA. Monitor query volume, source utilization, and performance from a Splunk dashboard. - [PSA Splunk Integration](https://knowledge.threatconnect.com/docs/polarity-psa-splunk-integration.md): Configure Polarity Source Analytics (PSA) Splunk integration to export usage metrics, query volume, and telemetry data for monitoring and consumption tracking. - [Polarity Source Analytics with Elasticsearch](https://knowledge.threatconnect.com/docs/polarity-source-analytics-with-elasticsearch.md): Forward Polarity PSA telemetry data to Elasticsearch. Index source usage metrics and query logs for visibility into integration activity and consumption. - [PSA Elasticsearch Integration](https://knowledge.threatconnect.com/docs/polarity-psa-elasticsearch-integration.md): Configure Polarity Source Analytics (PSA) Elasticsearch integration to index usage metrics, telemetry, and query logs for monitoring integration consumption. - [Creating an API Token](https://knowledge.threatconnect.com/docs/polarity-create-rest-api-token.md): Learn how to generate and configure REST API tokens in Polarity Server v5 for programmatic access. Create API credentials to authenticate requests, integrate external systems, and automate annotation workflows with Polarity's API endpoints. - [Channels](https://knowledge.threatconnect.com/docs/polarity-rest-api-channels.md): Learn how to manage Polarity Server v5 channels (team workspaces) via REST API. Create, read, update, and delete shared annotation spaces and team collaboration areas using API endpoints and authentication tokens. - [Annotations](https://knowledge.threatconnect.com/docs/polarity-rest-api-annotations.md): Learn how to create, read, update, and delete annotations (tags, notes, labels) in Polarity Server v5 via REST API endpoints. Complete API reference with examples for programmatic annotation management and integration. - [Searching Polarity Integrations](https://knowledge.threatconnect.com/docs/polarity-rest-api-searching-integrations.md): Learn how to search and query Polarity Server v5 integrations using the REST API. Find API endpoints, parameters, and code examples for discovering plugins, connectors, and data sources through programmatic calls. - [Integration Attributes](https://knowledge.threatconnect.com/docs/polarity-rest-api-integration-attributes.md): Learn how to retrieve and configure integration attributes in Polarity Server v5 using the REST API. Find API endpoints, parameters, and response formats for managing connector properties and data source settings. - [Updating Integrations](https://knowledge.threatconnect.com/docs/polarity-rest-api-updating-integrations.md): Polarity Server v5 REST API guide for updating and modifying integrations. Learn how to manage plugins, connectors, and data sources programmatically using API endpoints and authentication tokens. - [Updating Integration Permissions](https://knowledge.threatconnect.com/docs/polarity-rest-api-updating-integration-permissions.md): Polarity Server v5 REST API guide for updating integration permissions. Learn how to modify plugin and connector access rights, manage API tokens, and configure data source authentication programmatically. - [Integration Options](https://knowledge.threatconnect.com/docs/polarity-rest-api-integration-options.md): Learn REST API endpoints to retrieve and manage Polarity Server v5 integrations, plugins, and data source connectors. Find API documentation for configuring custom integrations and viewing active plugin status. - [Updating Polarity Server v5 to the Latest Release](https://knowledge.threatconnect.com/docs/polarity-updating-server-v5-to-the-latest-release.md): Learn how to upgrade Polarity Server v5 to the latest release. Step-by-step instructions for updating your Docker or Podman deployment with minimal downtime. - [Troubleshooting Polarity v5](https://knowledge.threatconnect.com/docs/polarity-troubleshooting-v5.md): Resolve common issues with Polarity Server v5 deployment and administration. Find error diagnostics, Docker troubleshooting steps, and server configuration fixes to restore annotation platform functionality. - [Polarity Server Logs](https://knowledge.threatconnect.com/docs/polarity-server-logs.md): Find and interpret Polarity server log files. Covers log locations, formats, verbosity levels, and how to use logs for troubleshooting and monitoring. - [Team Management](https://knowledge.threatconnect.com/docs/polarity-administrator-team-management-1.md): Learn how to manage teams, assign user roles, and configure access controls in Polarity Enterprise administrator settings. - [Tasks](https://knowledge.threatconnect.com/docs/polarity-administrator-tasks-1.md) - [Server Configuration](https://knowledge.threatconnect.com/docs/polarity-administrator-server-configuration-1.md) - [Back Up or Restore a Polarity Server](https://knowledge.threatconnect.com/docs/polarity-server-backup-restore.md): Learn how to back up and restore your Polarity Server v5 deployment. Step-by-step procedures for protecting annotations, configurations, and team data in Docker or Podman environments. Ensure business continuity and disaster recovery. - [Migrate a Polarity Server](https://knowledge.threatconnect.com/docs/polarity-server-migrate.md): Learn how to migrate your Polarity Server v5 deployment to a new environment or hardware. This guide covers backup procedures, data transfer, and restore steps for Docker and Podman deployments. - [Advanced Polarity Client Installation](https://knowledge.threatconnect.com/docs/polarity-advanced-client-installation.md): Learn advanced Polarity Server v5 client installation steps, system requirements, and deployment configuration for administrators setting up the platform in enterprise environments. - [Roll-Back Polarity Updates](https://knowledge.threatconnect.com/docs/polarity-roll-back-updates.md): Learn how to downgrade or revert Polarity Server v5 to a previous version after a failed update. Step-by-step rollback procedures for Docker and Podman deployments to restore system stability. - [Custom Entity Types](https://knowledge.threatconnect.com/docs/polarity-custom-entity-types.md): Configure custom entity types in Polarity Server v5 to extend annotation and tagging capabilities. Learn how to define custom data types, create new annotation categories, and customize entity schemas for your team's threat intelligence needs. - [Manually Set Up Let's Encrypt with Polarity Server v5](https://knowledge.threatconnect.com/docs/polarity-manually-set-up-lets-encrypt-with-server-v5.md): Learn how to manually configure Let's Encrypt SSL/TLS certificates for Polarity Server v5 deployment. Step-by-step guide for HTTPS security configuration and certificate management in Docker or Podman environments. - [Polarity Nexus](https://knowledge.threatconnect.com/docs/polarity-nexus-guide.md): Learn to configure and manage Polarity Nexus in Polarity Server v5. This advanced administration guide covers system setup, deployment architecture, and enterprise-level configuration for team collaboration and annotation workflows. - [Email Template Configuration](https://knowledge.threatconnect.com/docs/polarity-email-template-configuration.md): Configure custom email templates and notification messages in Polarity Server v5. Set up SMTP settings, customize alerts, and manage email delivery for team notifications and system messages. - [Offline Integration Store](https://knowledge.threatconnect.com/docs/polarity-offline-integration-store.md): Learn to set up and manage Polarity Server v5's offline integration store for air-gapped environments. Download, install, and deploy plugins and connectors without internet access. - [Polarity Server v5 (Platform)](https://knowledge.threatconnect.com/docs/polarity-platform-v5.md): Polarity Server v5 is the current server-based annotation platform. Learn deployment options (Docker/Podman), system requirements, installation steps, and upgrade paths for enterprise threat-intelligence annotation and team collaboration. - [Polarity Web V5 (UI)](https://knowledge.threatconnect.com/docs/polarity-web-v5.md): Polarity Web V5 is the current web-based user interface for the Polarity annotation platform. Discover UI updates, new features, improvements to real-time annotation, team collaboration tools, and how to work with channels and annotations in the web client. - [Polarity Desktop Client v5](https://knowledge.threatconnect.com/docs/polarity-desktop-client.md): Install and configure Polarity Desktop Client v5, the lightweight annotation tool for real-time threat intelligence markup. Learn system requirements, download options, and initial setup for team collaboration. - [Community Edition Setup](https://knowledge.threatconnect.com/docs/community-edition-setup.md): Install and deploy Polarity Community Edition, the free lightweight annotation platform. Learn Docker/Podman setup, initial configuration, and how to start collaborating with your team on threat intelligence annotations. - [Enterprise Desktop Client Setup](https://knowledge.threatconnect.com/docs/enterprise-desktop-client-setup.md): Install and configure the Polarity General desktop client for Windows, macOS, or Linux. Learn deployment steps, system requirements, and team workspace connection for enterprise annotation and threat intelligence collaboration. - [Polarity Web Interface](https://knowledge.threatconnect.com/docs/polarity-web-interface.md): Learn how to use Polarity General's web interface to access the annotation platform via browser. Discover dashboard navigation, team channels, shared workspaces, and core features for collaborative threat intelligence annotation and labeling. - [Browser Plugin](https://knowledge.threatconnect.com/docs/browser-plugin.md): Learn how to install and use Polarity's browser plugin to auto-detect and annotate indicators in real-time as you browse. Extend live highlighting and threat intelligence directly into your browser workflow. - [Polarity Practical Use Case Exercises](https://knowledge.threatconnect.com/docs/practical-polarity-use-cases.md): Learn Polarity General through hands-on exercises and real-world threat investigation scenarios. Practice annotation workflows, tag labeling, and team collaboration features in actionable use cases. - [Learning Library](https://knowledge.threatconnect.com/docs/learning-library.md): Access Polarity's comprehensive learning library with tutorials, guides, and training materials to get started with the annotation platform. Find how-to resources, best practices, and educational content for team collaboration and threat intelligence workflows. - [Security Operations Centers](https://knowledge.threatconnect.com/docs/security-operations-centers.md): Learn how Polarity General accelerates SOC workflows with real-time threat detection, team annotation, and collaborative incident response. Enhance threat intelligence sharing across your security operations center. - [Threat Intelligence Teams](https://knowledge.threatconnect.com/docs/threat-intelligence-teams.md): Learn how Polarity General enables threat intelligence teams to collaborate in shared workspaces (channels) for real-time annotation, tag, and label sharing. Discover best practices for team-based threat analysis and intelligence workflows. - [Offensive Security and Vulnerability Management](https://knowledge.threatconnect.com/docs/offensive-security-and-vulnerability-management.md): Learn how Polarity General helps security teams identify, assess, and remediate vulnerabilities through offensive security practices. Discover how to integrate vulnerability scanning, pentesting tools, and threat intelligence for comprehensive risk management. - [ThreatConnect Risk Quantifier FAQ](https://knowledge.threatconnect.com/docs/threatconnect-risk-quantifier-faq.md): This article provides a list of frequently asked questions (FAQ) related to ThreatConnect Risk Quantifier. - [RQ 7.8 and 7.9 Release Notes](https://knowledge.threatconnect.com/docs/rq-78-and-79-release-notes-1.md): This article provides a PDF file of the ThreatConnect Risk Quantifier (RQ) 7.7 release notes. - [RQ 7.7 Release Notes](https://knowledge.threatconnect.com/docs/rq-77-release-notes-1.md): This article provides a PDF file of the ThreatConnect Risk Quantifier (RQ) 7.7 release notes. - [RQ 7.6 Release Notes](https://knowledge.threatconnect.com/docs/rq-76-release-notes-1.md): This article provides a PDF file of the ThreatConnect Risk Quantifier (RQ) 7.6 release notes. - [RQ 7.0 Release Notes](https://knowledge.threatconnect.com/docs/rq-70-release-notes-1.md): This article provides a PDF file of the ThreatConnect Risk Quantifier (RQ) 7.0 release notes. - [FAIR - Primary Loss Magnitude Values Definitions](https://knowledge.threatconnect.com/docs/fair-primary-loss-magnitude-values-definitions.md): This article provides definitions for the loss types listed on the FAIR – Primary Loss Magnitude Values tab of the Model Tuning screen within the settings for a Legal Entity in ThreatConnect Risk Quantifier. - [Loss Variables Definitions](https://knowledge.threatconnect.com/docs/loss-variables-definitions.md): This article provides definitions for the loss types listed on the Loss Variables tab of the Model Tuning screen within the settings for a Legal Entity in ThreatConnect Risk Quantifier. - [ThreatConnect Risk Quantifier User Roles and Permissions](https://knowledge.threatconnect.com/docs/threatconnect-risk-quantifier-user-roles-and-permissions.md): This article defines the user roles in ThreatConnect Risk Quantifier (RQ) and the permissions associated with each role.