Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Define threat groupings

Define threat groupings as objects that have a shared context.

Before you begin

Role required: sn_ti.admin

Procedure

  1. Navigate to All > Threat Intelligence > IoC Repository > Threat Groupings.

  2. Click New.

  3. Complete the fields in the form as appropriate.

    FieldDescription
    NameEnter a name to identify the threat grouping.
    ContextA description of the particular context shared by the content referenced by the grouping.
    SourceSpecifies the threat source from which this record is created.
    DescriptionA short description that provides details and context about the grouping. This includes its purpose and its key characteristics.
    Source IDUnique identifier for this object in the threat source.
    Created Time in SourceSpecifies the time the object is created in the source.
    Modified Time in SourceSpecifies the time the object is modified in the source.
  4. Click Submit.

What to do next

Click any of the following related lists to view additional information about objects associated with the threat grouping.

Related Links and Related ListsDescription
Show RelationshipsOpens the STIX Visualizer where you can view the relationship of the STIX object.Show Relationships appears only when the object has an associated object.
Grouped ObjectsLists objects grouped as part of the threat grouping.
Grouped IndicatorsLists indicators grouped as part of the threat grouping.
Grouped ObservablesLists observables grouped as part of the threat grouping.

Parent Topic:Threat groupings