Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Define Location

Define a geographic location to provide more context to other SDOs.

Before you begin

Role required: sn_ti.admin

Procedure

  1. Navigate to All > Threat Intelligence > IoC Repository > Locations.

  2. Click New.

  3. Complete the fields in the form as appropriate.

FieldDescription
NameEnter a descriptive name to identify the location.
Street AddressThe street address that this location describes. This property includes all aspects or parts of the street address.
CityThe city that this location is in.
Postal CodeThe postal code that this location is in.
RegionThe region that this location is in.
CountryThe country that this location is in.
LatitudeThe latitude of the Location in decimal degrees. Positive numbers describe latitudes north of the equator, and negative numbers describe latitudes south of the equator. The value of this property must be from -90.0 through 90.0 respectively.
LongitudeThe longitude of the location in decimal degrees. Positive numbers describe longitudes east of the prime meridian and negative numbers describe longitudes west of the prime meridian. The value of this property must be from -180.0 through 180.0, inclusive.
SourceSpecifies the threat source from which this record is created.
DescriptionA description that provides more details and context about the intrusion set, potentially including its purpose and its key characteristics.
Source IDUnique identifier for this object in the threat source.
Created Time in SourceSpecifies the time the object is created in the source.
Modified Time in SourceSpecifies the time the object is modified in the source.
  1. Click Submit.

What to do next

Click any of the following related lists to view additional information about objects associated with the location.

Related Links and Related ListsDescription
Show RelationshipsOpens the STIX Visualizer where you can view the relationship of the STIX object.Show Relationships appears only when the object has an associated object.
External ReferencesLists external references which refer to non-STIX information. This property is used to provide one or more external object identifiers.
Attack PatternsLists the attack patterns that help categorize attacks that are associated with this object.
CampaignsLists campaigns associated with this object.
IdentitiesList of identities associated with this object.
InfrastructureLists systems, software services, and any associated physical or virtual resources that are associated with this object.
Intrusion SetLists a set of adversarial behaviors and resources with common properties associated with this object.
MalwareLists malicious code associated with this object.
Threat ActorsLists individuals, groups, or organizations who act with malicious intent associated with this object.
ToolsLists legitimate software that is used by threat actors to perform attacks associated with this object.

Parent Topic:Locations