Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Define threat reports

Define threat reports that describe a threat actor, malware, attack technique, including context and related details.

Before you begin

Role required: sn_ti.admin

Procedure

  1. Navigate to All > Threat Intelligence > IoC Repository > Threat Reports.

  2. Click New.

  3. Complete the fields in the form as appropriate.

    FieldDescription
    NameSpecify a name to identify the threat report.
    PublishedThe date that this report has been officially published by the report author.
    DescriptionA description that provides additional insight and context about the report.
    SourceSpecifies the threat source from which this record is created.
    Source IDUnique identifier for this object in the threat source.
    Created Time in SourceSpecifies the time the object is created in the source.
    Modified Time in SourceSpecifies the time the object is modified in the source.
  4. Click Submit.

What to do next

Click any of the following related lists to view additional information about objects associated with the threat reports.

Related Links and Related ListsDescription
Show RelationshipsOpens the STIX Visualizer where you can view the relationship of the STIX object.Show Relationships appears only when the object has an associated object.
Associated TypesLists indicator types associated with this object.
Reported ObjectsList of objects reported in the threat report.
Reported IndicatorsLists of indicators reported in the threat report.
Reported ObservablesLists of observables reported in the threat report.

Parent Topic:Threat reports