Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Define tools

Define tools as legitimate software that is used to perform attacks.

Before you begin

Role required: sn_ti.admin

Procedure

  1. Navigate to All > Threat Intelligence > IoC Repository > Tools.

  2. Click New.

  3. Complete the fields in the form as appropriate.

    FieldDescription
    NameEnter a descriptive name to identify the tool.
    SourceSpecifies the threat source from which this record is created.
    DescriptionA description that provides more details and context about the tool, potentially including its purpose and its key characteristics.
    AliasesAlternative names to identify this tool.
    Source IDUnique identifier for this object in the threat source.
    Created Time in SourceSpecifies the time the object is created in the source.
    Modified Time in SourceSpecifies the time the object is modified in the source.
  4. Click Submit.

What to do next

Click any of the following related lists to view additional information about objects associated with the tool object.

Related Links and Related ListsDescription
External ReferencesLists external references which refer to non-STIX information. This property is used to provide one or more external object identifiers.
Associated Kill Chain PhasesLists kill chain phases associated with this object.
Associated TypesLists indicator types associated with this object.
Attack PatternsLists the attack patterns that help categorize attacks that are associated with this object.
CampaignsLists campaigns associated with this object.
Course of ActionsLists the associated course of actions with this object that are technical or automated responses \(applying patches, reconfiguring firewalls\) to prevent an attack.
IdentitiesList of identities associated with this object.
IndicatorsLists related Indicators of Compromise \(IoC\) that have been identified by the threat source associated with this object.
InfrastructureLists systems, software services, and any associated physical or virtual resources that are associated with this object.
Intrusion SetLists a set of adversarial behaviors and resources with common properties associated with this object.
LocationsLists locations that provide geographic context to this object.
MalwareLists malicious code associated with this object.
Threat ActorsLists individuals, groups, or organizations who act with malicious intent associated with this object.
VulnerabilitiesLists a weakness or defect in a software or hardware that attackers exploit which is associated with this object.
Show RelationshipsOpens the STIX Visualizer where you can view the relationship of the STIX object.Show Relationships appears only when the object has an associated object.

Parent Topic:Tools