Define a campaign
Define a campaign to group adversarial behaviors.
Before you begin
Role required: sn_ti.admin
Procedure
Navigate to All > Threat Intelligence > IoC Repository > Campaigns.
Click New.
Complete the fields in the form as appropriate.
| Field | Description |
|---|---|
| Name | Enter a descriptive name for this campaign. |
| Spec Version | The version of the STIX specification used to represent this object.The value of this property must be 2.1 for STIX Objects defined according to this specification. |
| Source | Specifies the threat source from which this record is created. |
| Description | A description that provides more details and context about the campaign. This includes its purpose and its key characteristics. |
| Aliases | Alternative names to identify this campaign. |
| Objective | The campaign’s primary goal, objective, desired outcome, or intended effect. What the threat actor or intrusion set hopes to accomplish with this campaign. |
| Source ID | Unique identifier for this object in the threat source. |
| Created Time in Source | Specifies the time the object is created in the source. |
| Modified Time in Source | Specifies the time the object is modified in the source. |
- Click Submit.
What to do next
You can now click any of the following related lists to view additional information about objects associated with the campaign.
| Related Links and Related Lists | Description |
|---|---|
| Show Relationships | Opens the STIX Visualizer where you can view the relationship of the STIX object.Show Relationships appears only when the object has an associated object. |
| External References | Lists external references which refer to non-STIX information. This property is used to provide one or more external object identifiers. |
| Attack Patterns | Lists the attack patterns that help categorize attacks that are associated with this object. |
| Identities | List of identities associated with this object. |
| Indicators | Lists related Indicators of Compromise \(IoC\) that have been identified by the threat source associated with this object. |
| Infrastructure | Lists systems, software services, and any associated physical or virtual resources that are associated with this object. |
| Intrusion Set | Lists a set of adversarial behaviors and resources with common properties associated with this object. |
| Locations | Lists locations that provide geographic context to this object. |
| Malware | Lists malicious code associated with this object. |
| Threat Actors | Lists individuals, groups, or organizations who act with malicious intent associated with this object. |
| Tools | Lists legitimate software that is used by threat actors to perform attacks associated with this object. |
| Vulnerabilities | Lists a weakness or defect in a software or hardware that attackers exploit which is associated with this object. |
Parent Topic:Campaigns