Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Threat groupings

A Threat Groupings object explicitly asserts that the referenced STIX Objects have a shared context. Threat groupings applies for STIX 2.x.

A Threat Groupings object represents a set of data that, given sufficient analysis, matures to convey an incident or threat report as a STIX Report object. For example, a Grouping could be used to characterize an ongoing investigation into a security event or incident.

A Threat Groupings object could also be used to assert that the referenced STIX Objects are related to an ongoing analysis process. For example, a threat analyst may collaborate with others in their trust community to examine a series of Campaigns and Indicators.

The Threat Grouping SDO contains a list of references to SDOs, SCOs, and SROs, along with an explicit statement of the context shared by the content, a textual description, and the name of the grouping.

Parent Topic:IoC Repository

Related topics

Attack modes and methods

Indicators of compromise

Observables

Attack patterns

Campaigns

Course of actions

Identities

Infrastructure

Intrusion set

Locations

Malware

Malware analysis

Observed data

Threat actors

Marking definitions

Threat notes

Threat opinions

Threat reports

Sightings

Tools

Vulnerabilities

Relationships

STIX Visualizer