The Details Drawer
  • 01 Aug 2023
  • 7 Minutes to read
  • Dark
    Light

The Details Drawer

  • Dark
    Light

Article Summary

When viewing Indicators, Groups, Tags, Tracks, Victims, or Victim Assets on the Browse screen, you can click on an object to display its Details drawer and view a detailed overview of the object. For example, Figure 1 shows the Details drawer for the badguy.com Host Indicator.

Figure 1_The Details Drawer_7.1.3

 

Details Drawer Sections

The Details drawer displays several sections with relevant information for the object you are viewing. Depending on the object’s type, the sections and elements displayed on this drawer will vary.

Indicators

Table 1 provides a description of each section that may be displayed on the Details drawer for an Indicator and the Indicator type(s) for which each section is available.

 

NameDescriptionApplicable Indicator Type(s)
AddedThe date when the Indicator was created.All
Associated IndicatorsThe Indicator(s) associated to the Indicator. If there are more than 10 associated Indicators, a link labeled all associated indicators... will be displayed at the bottom of this section. Click it to display the Associations tab of the Indicator’s Details screen and view all associated Indicators.All
Associated IntelThe Group(s) associated to the Indicator.All
Associated Victim AssetsThe Victim Asset(s) associated to the Indicator.All
AttributesThe Attribute(s) added to the Indicator.All
CAL™ InsightsThe data retrieved from CAL for the Indicator. To expand and collapse a section under the CAL™ Insights heading, click on the respective section heading.All
Confidence RatingThe Indicator’s Confidence Rating.All
DescriptionIf a default Description Attribute has been added to the Indicator, it will be displayed above the Type, Owner, Added, and Last Modified sections.All
DNSThis section specifies whether the DNS resolution tracking feature is active for the Host Indicator.Host
Explore in GraphClick the Explore in Graph button to view the Indicator in Threat Graph.All
False PositivesThe number of times the Indicator was reported as a false positive.All
Indicator StatusThis section, located at the upper-left corner of the drawer, displays the Indicator Status for the Indicator and specifies whether it was set by ThreatConnect or CAL.All
Investigation LinksA list of links to search results of various third-party lookup and other information services. Each link is a shortcut to query results for the Indicator, which will open in a new browser tab.All
Last ModifiedThe date when the Indicator was last modified.All
ObservationsThe number of times the Indicator was observed by an API user.All
OwnerThe Organization, Community, or Source to which the Indicator belongs.All
Security LabelsThe Security Label(s) applied to the Indicator.All
TagsThe Tag(s) applied to the Indicator.All
Threat RatingThe Indicator’s Threat Rating.All
ThreatAssessThe Indicator’s ThreatAssess score and data related to that score.All
TypeThe Indicator’s type.All
WhoisThis section specifies whether the WHOIS feature is active for the Host Indicator.Host

Groups

Table 2 provides a description of each section that may be displayed on the Details drawer for a Group and the Group type(s) for which each section is available.

 

NameDescriptionApplicable Group Type(s)
AddedThe date when the Group was created.All
AssigneesThe user(s) assigned to the Task.Task
Associated IndicatorsThe Indicator(s) associated to the Group. If there are more than 10 associated Indicators, a link labeled all associated indicators... will be displayed at the bottom of this section. Click it to display the Associations tab of the Group’s Details screen and view all associated Indicators.All
Associated IntelThe Group(s) associated to the Group.All
Associated Victim AssetsThe Victim Asset(s) associated to the Group.All
AttributesThe Attribute(s) added to the Group.All
Create Custom ReportClick the Create Custom Report button to create a report for the Group.All
DescriptionIf a default Description Attribute has been added to the Group, it will be displayed above the Type, Owner, Added, and Last Modified sections.All
Due DateThe date when the Task is due.Task
Email InformationThis section displays the following information for the Email Group: the Threat Score of the Email, the sender’s email address, the date when the Email was sent, and the Email’s subject.Email
Event DateThe date when the Event or Incident took place.Event; Incident
File InformationFor Document and Report Groups, this section displays the name, type, and size of the file uploaded to the Group; the status of the file upload; and the date when the file was last modified.

For Signature Groups, this section displays the name and format of the signature file corresponding to the Group and the date when the file was last modified.
Document; Report; Signature
First SeenThe date when the Campaign was first seen.Campaign
Last ModifiedThe date when the Group was last modified.All
OwnerThe Organization, Community, or Source to which the Group belongs.All
Security LabelsThe Security Label(s) applied to the Group.All
StatusThe status of the Event, Incident, or Task.Event; Incident; Task
TagsThe Tag(s) applied to the Group.All
TypeThe Group’s type.All
Visual AnalysisClick the Visual Analysis button to display a menu with the following options:All

Tags

Table 3 provides a description of each section that may be displayed on the Details drawer for a Tag.

 

NameDescription
Associated IndicatorsThe Indicator(s) to which the Tag is applied. If there are more than 10 Indicators, a link labeled all associated indicators... will be displayed at the bottom of this section. Click it to display the Tag’s legacy Details screen and view all Indicators to which it is applied on the Associations card .
Associated IntelThe Group(s) to which the Tag is applied.
Associated VictimsThe Victim(s) to which the Tag is applied.
Explore in GraphClick the Explore in Graph button to view the Tag in Threat Graph.
Last UsedThe date when the Tag was last used. For Tags that have not been used since the Last Used date was introduced in ThreatConnect, this section will display a value of Unknown.
OwnerThe Organization, Community, or Source to which the Tag belongs.
SummaryThe Tag’s summary.
Synonymous Tags
This section is displayed only for main Tags defined in Tag normalization rules (i.e., Tags with anMain Tag icon_Browse Screenicon displayed to the left of their name in the Summary column on the Browse screen) and provides a list of synonymous Tags associated with the main Tag.
TypeThis section will always display a value of “Tag.”

Tracks

Table 4 provides a description of each section that may be displayed on the Details drawer for a Track.

 

NameDescription
ActiveThis section specifies whether the Track is active.
AddedThe date when the Track was created.
DescriptionIf a description has been added to the Track, it will be displayed above the Type, Owner, Added, and Active sections.
OwnerThe Organization, Community, or Source to which the Track belongs.
ResultsThe number of results for the Track.
TypeThis section will always display a value of “Track.”

Victims

Table 5 provides a description of each section that may be displayed on the Details drawer for a Victim.

 

NameDescription
AssetsThe Victim Asset(s) added to the Victim. Victim Asset(s) are also displayed in the Associated Victim Assets section.
Associated IndicatorsThe Indicator(s) associated to one or more of the Victim’s Assets. If there are more than 10 associated Indicators, a link labeled all associated indicators... will be displayed at the bottom of this section. Click it to display the Victim’s legacy Details screen and view all associated Indicators on the Associations card .
Associated IntelThe Group(s) associated to one or more of the Victim’s Assets.
Associated Victim AssetsThe Victim Asset(s) added to the Victim. Victim Asset(s) are also displayed in the Assets section.
AttributesThe Attribute(s) added to the Victim.
DescriptionIf a default Description Attribute has been added to the Victim, it will be displayed above the Type, Owner, Victim Organization, and Sub-Organization sections.
NationalityThe Victim’s nationality.
OwnerThe Organization, Community, or Source to which the Victim belongs.
Security LabelsThe Security Label(s) applied to the Victim.
Sub-OrganizationThe Victim’s sub-organization.
TagsThe Tag(s) applied to the Victim.
TypeThis section will always display a value of “Victim.”
Victim OrganizationThe Victim’s organization.
Work LocationThe Victim’s work location.

Victim Assets

Table 6 provides a description of each section that may be displayed on the Details drawer for a Victim Asset.

 

NameDescription
AssetFor Email Address, Network Account, and Social Network Victim Assets, this section will display the corresponding account type, if one has been provided; for Phone and Website Victim Assets, this section will always display a value of “None,” as you cannot specify an account type for these Victim Asset types.
Associated IndicatorsThe Indicator(s) associated to the Victim Asset. If there are more than 10 associated Indicators, a link labeled all associated indicators... will be displayed at the bottom of this section. Click it to display the legacy Details screen for the Victim to which the Victim Asset belongs and view all associated Indicators on the Associations card .
Associated IntelThe Group(s) associated to the Victim Asset.
TypeThis Victim Asset’s type.
VictimThe Victim to which the Victim Asset belongs.

Pivoting From the Details Drawer

If viewing the Details drawer for an Indicator, Group, or Tag, click the vertical ellipsis at the upper-right corner of the drawer and select Pivot to pivot from the object and view its associated objects on the Browse screen.

Accessing the Details Screen From the Details Drawer

To view the Overview tab of the object’s Details screen, click View full detailsView full details_Details drawerat the upper-right corner of the Details drawer. Alternatively, hover over the object’s entry in the table on the Browse screen and click one of the following icons displayed in its Summary cell (Figure 2):

Figure 2_The Details Drawer_7.1.3

 

  • View full detailsView full details_Browse: Click this icon to open the object’s Details screen in the current browser tab.
  • View details in new tabView full details in new tab icon: Click this icon to open the object’s Details screen in a new browser tab.
Note
For a Victim Asset, no icons are displayed when you hover over its entry in the table on the Browse screen. Instead, you must click on its entry in the table to display its Details drawer and then click the View full detailsView full details_Details drawericon at the upper-right corner of the drawer, which will display the Details screen for the Victim to which the Victim Asset belongs.

ThreatConnect® is a registered trademark, and CAL™ is a trademark, of ThreatConnect, Inc.
MITRE ATT&CK® and ATT&CK® are registered trademarks of The MITRE Corporation.

20051-03 v.16.B


Was this article helpful?