<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>ThreatConnect Knowledge Base</title>
    <description />
    <link>https://knowledge.threatconnect.com/docs</link>
    <atom:link href="https://knowledge.threatconnect.com/rss/en" rel="self" type="application/rss+xml" />
    <item>
      <title>Polarity Desktop Client v5</title>
      <description>V5.1.6Page actionsAbout Latest VersionVersion 5.1.6 introduces SAML authentication through the browser, updates Polarity sign in page designs and address some issues. New Features and Functionality Sign In Page UI redesign We have updated the UI of the sign in pages to match that of our web design: SAML Authentication through browser In order to enable Polarity users to authenticate through SAML with multiple different SAML setups, we have enabled the Polarity client to authenticate through the  ...</description>
      <pubDate>Wed, 16 Sep 2026 01:02:21 GMT</pubDate>
      <category>Polarity &gt; Polarity Release Notes</category>
      <link>https://knowledge.threatconnect.com/docs/polarity-desktop-client</link>
      <guid>https://knowledge.threatconnect.com/docs/polarity-desktop-client</guid>
    </item>
    <item>
      <title>Dataminr CTTI Intelligence Engine User Guide</title>
      <description>Overview
This article is a user guide for the Dataminr CTTI Intelligence Engine integration with Dataminr Agentic Threat Intelligence Platform (ATIP). The Dataminr CTTI Intelligence Engine feed API service app ingests cyber threat intelligence alerts, and the cyber entities those alerts reference, from Dataminr Cyber Threat Intelligence (CTTI) and creates corresponding objects in Agentic TIP with select Dataminr metadata:

Alerts are created as Event Groups in Agentic TIP.
Malware entities are c ...</description>
      <pubDate>Tue, 15 Sep 2026 13:51:09 GMT</pubDate>
      <category>ThreatConnect Platform &gt; Apps and Integrations &gt; Premium Threat Intelligence Feed Integrations</category>
      <link>https://knowledge.threatconnect.com/docs/dataminr-ctti-intelligence-engine-user-guide</link>
      <guid>https://knowledge.threatconnect.com/docs/dataminr-ctti-intelligence-engine-user-guide</guid>
    </item>
    <item>
      <title>Feedly Intelligence Engine Integration User Guide</title>
      <description>Software VersionThis guide applies to the Feedly Intelligence Engine App version 1.0.5.What's new in v1.0.5Article stream ingestion as Reports. The App now has a second ingestion path, alongside the existing STIX ingestion, that pulls raw articles from any Feedly stream and writes them into ThreatConnect as Report groups, whether or not Feedly enriched the article into STIX. Configured with the new Article Stream ID(s) field. See Application Setup and Configuration and Article Field Mapping.Arti ...</description>
      <pubDate>Tue, 15 Sep 2026 11:06:46 GMT</pubDate>
      <category>ThreatConnect Platform &gt; Apps and Integrations &gt; Premium Threat Intelligence Feed Integrations</category>
      <link>https://knowledge.threatconnect.com/docs/feedly-intelligence-engine-integration-user-guide</link>
      <guid>https://knowledge.threatconnect.com/docs/feedly-intelligence-engine-integration-user-guide</guid>
    </item>
    <item>
      <title>TQL Operators and Parameters</title>
      <description>OverviewA ThreatConnect® Query Language (TQL) query expression includes a parameter name, an operator, and a value or list of values, and you can combine multiple query expressions using parentheses and AND/OR logic. This article provides a list of all TQL operators and parameters available in ThreatConnect.NoteA value’s case sensitivity may depend on database deployment type, the operator being applied to it, or other factors.OperatorsTable 1 describes the ThreatConnect Query Language (TQL) ope ...</description>
      <pubDate>Mon, 14 Sep 2026 20:54:58 GMT</pubDate>
      <category>ThreatConnect Platform &gt; Threat Intelligence &gt; ThreatConnect Query Language (TQL)</category>
      <link>https://knowledge.threatconnect.com/docs/tql-operators-and-parameters</link>
      <guid>https://knowledge.threatconnect.com/docs/tql-operators-and-parameters</guid>
    </item>
    <item>
      <title>8.1 Release Notes</title>
      <description>ImportantThis article contains the current version of the ThreatConnect® release notes for version 8.1, including all currently available patches. The most recent version is 8.1.1-M0902R. See the Maintenance Releases Changelog section for a list of updates made for patch versions after the 8.1 release.New Features and FunctionalityThreatConnect 8.1 builds upon the Agentic Threat Intelligence Platform (ATIP) foundation introduced as an early-beta feature in version 8.0. This release extends the a ...</description>
      <pubDate>Fri, 11 Sep 2026 20:40:59 GMT</pubDate>
      <category>Release Notes &gt; ThreatConnect Platform Release Notes</category>
      <link>https://knowledge.threatconnect.com/docs/8-1-release-notes</link>
      <guid>https://knowledge.threatconnect.com/docs/8-1-release-notes</guid>
    </item>
    <item>
      <title>ThreatConnect Environment Server Installation Guide</title>
      <description>Software VersionThis guide applies to software version 2.2.10 of the ThreatConnect® Environment Server.OverviewMulti-environment orchestration (MEO) allows ThreatConnect® users that have an Environment Server behind a firewall to use their instance to communicate with that server and run applications inside their firewall. This article provides the system requirements and instructions for installing an instance of the ThreatConnect Environment Server. See Playbook Environments for information ab ...</description>
      <pubDate>Thu, 10 Sep 2026 20:53:00 GMT</pubDate>
      <category>ThreatConnect Platform &gt; Settings and Administration</category>
      <link>https://knowledge.threatconnect.com/docs/threatconnect-environment-server-installation-guide</link>
      <guid>https://knowledge.threatconnect.com/docs/threatconnect-environment-server-installation-guide</guid>
    </item>
    <item>
      <title>Polarity Server v5 (Platform)</title>
      <description>Polarity Server V5.3.4 (Latest)The latest 5.3.3 release of the Polarity Server is a server side patch that addresses some identified vulnerabilities, adds in support for TLS connections to Redis and PostgreSQL, fixed an issue with integration functions being called out of order, added the ability to configure SMTP without having setting a username. Issues AddressedAddressed issue with integration functions sometimes being called before the startup function causing integrations to stop. Addressed ...</description>
      <pubDate>Wed, 09 Sep 2026 19:21:03 GMT</pubDate>
      <category>Polarity &gt; Polarity Release Notes</category>
      <link>https://knowledge.threatconnect.com/docs/polarity-platform-v5</link>
      <guid>https://knowledge.threatconnect.com/docs/polarity-platform-v5</guid>
    </item>
    <item>
      <title>Polarity Web V5 (UI)</title>
      <description>Polarity Web (UI)</description>
      <pubDate>Wed, 09 Sep 2026 19:20:25 GMT</pubDate>
      <category>Polarity &gt; Polarity Release Notes</category>
      <link>https://knowledge.threatconnect.com/docs/polarity-web-v5</link>
      <guid>https://knowledge.threatconnect.com/docs/polarity-web-v5</guid>
    </item>
    <item>
      <title>Agentic TIP MCP Server README</title>
      <description># Dataminr - Agentic TIP MCP Server
Access Agentic TIP threat intelligence and case management data directly from Claude (or any MCP-compatible client) via the Agentic TIP v3 REST API.
Overview
The Agentic TIP MCP Server exposes your Agentic TIP instance's v3 API as a set of MCP tools over a hosted endpoint. Every Agentic TIP instance exposes POST /api/v3/mcp directly, and any MCP client that supports remote HTTP servers can connect to it.
Note

See the "TIP MCP Server" section of the 8.1 releas ...</description>
      <pubDate>Mon, 31 Aug 2026 19:49:41 GMT</pubDate>
      <category>ThreatConnect Platform &gt; TIP MCP Server</category>
      <link>https://knowledge.threatconnect.com/docs/agentic-tip-mcp-server-readme</link>
      <guid>https://knowledge.threatconnect.com/docs/agentic-tip-mcp-server-readme</guid>
    </item>
    <item>
      <title>Configure Proxies</title>
      <description>Configure proxy support either server wide or per integrationProxy configuration is required if your Polarity server needs proxy access to reach the Internet and you are running integrations that rely on Internet based services or resources. Proxy support can be enabled for integrations either on a server-wide basis or a per-integration basis. In general, integrations that will be connecting to internal resources do not need to have a proxy configured. Integrations that will be accessing Interne ...</description>
      <pubDate>Sat, 15 Aug 2026 00:06:59 GMT</pubDate>
      <category>Polarity &gt; Polarity Administrators Guide &gt; Polarity Server v5</category>
      <link>https://knowledge.threatconnect.com/docs/polarity-configuring-proxies</link>
      <guid>https://knowledge.threatconnect.com/docs/polarity-configuring-proxies</guid>
    </item>
    <item>
      <title>Server Environment Variables</title>
      <description>Server environment variables can be configured by modifying the `.env` file located at /app/.env.  Modifications to the .env file will require a restart of the Polarity Server's Docker containers:cd /app &amp;&amp; ./down.sh &amp;&amp; ./up.shVariablesMIX_ENV=prod
POLARITY_HOSTNAME={{hostname of Polarity server}}
POLARITY_HTTPS_PORT=4001
POLARITY_HTTP_PORT=4000
POLARITY_TLS_KEY_PATH=/app/certs/polarity_key.pem
POLARITY_TLS_CERT_PATH=/app/certs/polarity.pem
POLARITY_LICENSE=/app/license/polarity.lic
POLARITY_PUB ...</description>
      <pubDate>Tue, 11 Aug 2026 15:19:52 GMT</pubDate>
      <category>Polarity &gt; Polarity Administrators Guide &gt; Polarity Server v5</category>
      <link>https://knowledge.threatconnect.com/docs/polarity-server-environment-variables</link>
      <guid>https://knowledge.threatconnect.com/docs/polarity-server-environment-variables</guid>
    </item>
    <item>
      <title>CAL System Settings</title>
      <description>Coming soon! For now, see this section of the ThreatConnect 8.0 release notes.</description>
      <pubDate>Tue, 04 Aug 2026 18:18:43 GMT</pubDate>
      <category>ThreatConnect Platform &gt; Threat Intelligence &gt; CAL</category>
      <link>https://knowledge.threatconnect.com/docs/cal-system-settings</link>
      <guid>https://knowledge.threatconnect.com/docs/cal-system-settings</guid>
    </item>
    <item>
      <title>Recognition Modes</title>
      <description>Choose Your ModeThere are four ways to harness the power of Polarity. Choose the mode that’s right for you either from within the main window, the Polarity Overlay or via the Polarity icon in the system tray.On-Demand Only -- Real-time recognition is off but you can still execute a search in Polarity.Stream -- Polarity will automatically stream information in real-time to the overlay when more context is available.Highlight -- Information is highlighted in real-time. Hover on highlights to get m ...</description>
      <pubDate>Tue, 04 Aug 2026 17:29:14 GMT</pubDate>
      <category>Polarity &gt; Polarity Enterprise Users Guide</category>
      <link>https://knowledge.threatconnect.com/docs/recognition-modes</link>
      <guid>https://knowledge.threatconnect.com/docs/recognition-modes</guid>
    </item>
    <item>
      <title>Polarity Practical Use Case Exercises</title>
      <description>Polarity Use Case TrainingStep 1Place your overlay window over the recommended area of this page.Step 2:Scroll down to where you see the SIEM example.Place your overlay window over this block.Grab the corners of thee window and adjust the size if neededSIEMPolarity is meant to help augment your workflow, no matter what application you are looking at. This example is meant to showcase how Polarity can help to augment your workflow when looking at information in a SIEM product.Step 1Place your ove ...</description>
      <pubDate>Tue, 04 Aug 2026 17:20:37 GMT</pubDate>
      <category>Polarity &gt; Polarity Learning Center</category>
      <link>https://knowledge.threatconnect.com/docs/practical-polarity-use-cases</link>
      <guid>https://knowledge.threatconnect.com/docs/practical-polarity-use-cases</guid>
    </item>
    <item>
      <title>Enabling the MCP Server</title>
      <description>The Polarity AI feature, which powers both the built-in chat and LLM-optimized reducers for the MCP, is configured in the Admin panel under Server Configuration. You must be a Polarity administrator to access these settings.Step 1: Navigate to Model SettingsLog in to the Polarity web interface.Click Admin in the top navigation.Select Server Configuration.Click the Model Settings tab.Step 2: Enable AIToggle the AI-enabled switch to the on position. This activates the AI backend. Without this togg ...</description>
      <pubDate>Tue, 04 Aug 2026 16:58:08 GMT</pubDate>
      <category>Polarity &gt; Polarity MCP Server Guide</category>
      <link>https://knowledge.threatconnect.com/docs/polarity-mcp-enabling-the-ai-feature</link>
      <guid>https://knowledge.threatconnect.com/docs/polarity-mcp-enabling-the-ai-feature</guid>
    </item>
    <item>
      <title>Polarity MCP Server Guide</title>
      <description>This document covers the Polarity Model Context Protocol (MCP) server: what it is, how to enable and authenticate against it, the tools it exposes, how data is optimized for LLM consumption, and how to use the MCP as a foundation for building AI-powered security applications.
Audience: Polarity administrators configuring the AI feature, developers integrating external AI agents or tools with Polarity, and security engineers building agentic workflows on top of Polarity's integration data.
What I ...</description>
      <pubDate>Tue, 04 Aug 2026 16:57:17 GMT</pubDate>
      <category>Polarity &gt; Polarity MCP Server Guide</category>
      <link>https://knowledge.threatconnect.com/docs/polarity-mcp-server</link>
      <guid>https://knowledge.threatconnect.com/docs/polarity-mcp-server</guid>
    </item>
    <item>
      <title>Skills</title>
      <description>Ten Skills for PolarityAnalyst workflows for Claude, built on the Polarity integrations you already run. Your analysts already have the intel — it's just spread across 90+ integrations, checked one at a time. These ten skills turn that sprawl into a single conversation: point Claude at a suspicious email, a CVE list, or an account, and it enriches, correlates, and hands back a scored verdict. No new infrastructure — every skill runs on Polarity integrations already deployed.Each skill: parse the ...</description>
      <pubDate>Tue, 04 Aug 2026 16:54:48 GMT</pubDate>
      <category>Polarity &gt; Polarity MCP Server Guide</category>
      <link>https://knowledge.threatconnect.com/docs/polarity-mcp-skills</link>
      <guid>https://knowledge.threatconnect.com/docs/polarity-mcp-skills</guid>
    </item>
    <item>
      <title>Quick Start with Claude</title>
      <description>The Polarity AI Features that power the built-in chat and LLM-optimized reducers for the MCP are configured in the Admin panel under Server Configuration. You must be a Polarity administrator to access these settings.Client PrerequisitesNode.js 18 or later and npx must be available. On macOS:  brew install npmThe connector package @polarityio/mcp-connector) is fetched and run automatically via npx on each connection — no manual install requiredNetwork access to the Polarity server URL from this  ...</description>
      <pubDate>Tue, 04 Aug 2026 16:46:25 GMT</pubDate>
      <category>Polarity &gt; Polarity MCP Server Guide</category>
      <link>https://knowledge.threatconnect.com/docs/polarity-mcp-claude-quickstart</link>
      <guid>https://knowledge.threatconnect.com/docs/polarity-mcp-claude-quickstart</guid>
    </item>
    <item>
      <title>Installing Polarity Integrations</title>
      <description>Installing integrations on Polarity v5 has become much easier and more streamlined, as installation can be done though the UI.Install Integration through Store Polarity users and admins can now see all of our officially supported integrations right from the store as well as install update or view more information about those integrations on what they do! Admins can just navigate to the integration you want to install and hit the Install Button! Upload Integration through UI If there is a custom  ...</description>
      <pubDate>Tue, 04 Aug 2026 16:41:22 GMT</pubDate>
      <category>Polarity &gt; Polarity Administrators Guide &gt; Polarity Server v5</category>
      <link>https://knowledge.threatconnect.com/docs/polarity-installing-integrations</link>
      <guid>https://knowledge.threatconnect.com/docs/polarity-installing-integrations</guid>
    </item>
    <item>
      <title>Example Agent Instructions</title>
      <description>OverviewWhen editing an agent node in an agentic playbook, the settings on the Model tab allow you to configure how an agent takes in and processes information from upstream in the playbook. In particular, in the Agent Instructions field, you provide the agent with directions about how to behave and respond to the information it receives. This article provides three examples sets of Markdown-formatted agent instructions for your reference.Before You StartUser RolesTo create and edit agent nodes  ...</description>
      <pubDate>Mon, 03 Aug 2026 19:23:30 GMT</pubDate>
      <category>ThreatConnect Platform &gt; Playbooks &gt; Agentic Playbooks</category>
      <link>https://knowledge.threatconnect.com/docs/example-agent-instructions</link>
      <guid>https://knowledge.threatconnect.com/docs/example-agent-instructions</guid>
    </item>
  </channel>
</rss>