Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Define threat notes

Define threat notes that convey information to provide further context or analysis that is not available in existing objects.

Before you begin

Role required: sn_ti.admin

Procedure

  1. Navigate to All > Threat Intelligence > IoC Repository > Threat Notes.

  2. Click New.

  3. Complete the fields in the form as appropriate.

    FieldDescription
    AbstractSpecify a brief summary of the note content.
    ContentSpecifies the content of the note.
    AuthorsSpecifies the name of the author (example, an analyst).
    SourceSpecifies the threat source from which this record is created.
    Source IDUnique identifier for this object in the threat source.
    Created Time in SourceSpecifies the time the object is created in the source.
    Modified Time in SourceSpecifies the time the object is modified in the source.
  4. Click Submit.

What to do next

Click any of the following related lists to view additional information about objects associated with the threat notes.

Related Links and Related ListsDescription
Show RelationshipsOpens the STIX Visualizer where you can view the relationship of the STIX object.Show Relationships appears only when the object has an associated object.
Associated ObjectsLists of objects that the threat notes apply to.
Associated IndicatorsLists of indicators that the threat notes apply to.
Associated ObservablesLists observables associated with this object.

Parent Topic:Threat notes