Explore In Graph
  • 18 Sep 2024
  • 2 Minutes to read
  • Dark
    Light

Explore In Graph

  • Dark
    Light

Article summary

Overview

The Threat Graph feature in ThreatConnect® provides a graph-based interface that you can use to discover, visualize, and contextualize associations and relationships between Indicators, Groups, Cases, and Tags. Specifically, you can perform the following actions to gain a comprehensive picture of a threat in Threat Graph:

  • Pivot on Indicator, Group, Case, and Tag associations in ThreatConnect; Indicator and Group relationships that exist within CAL™; and third-party enrichment relationships for supported Indicator types
  • Run active UserAction Trigger–based Playbooks for Indicators that exist in ThreatConnect
  • Create Group-to-Group, Indicator-to-Group, and Group-to-Indicator associations
  • Import Indicators from Threat Graph into one of your ThreatConnect owners
  • View known alias information in CAL for select Group types and combine Group nodes that share an alias into a single node

After you build out a graph in Threat Graph, you can save the graph to revisit at a later time or add to a report, or you can export the graph as an image file that you can share with teammates, executives, and stakeholders.

In This Series


ThreatConnect® is a registered trademark, and CAL™ is a trademark, of ThreatConnect, Inc.

20117-01 v.08.A


Was this article helpful?