Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Sightings

Sightings denote that an indicator or object was seen. Objects may be a malware, tool, threat actor, and so on.

Sightings track who and what is the target, how attacks are carried out, and to track trends in attack behavior.

The Sighting relationship object contains extra properties not present in the generic relationship objects. These extra properties represent data specific to sighting relationships.

For example, a count, or representing how many times something was seen.

Sighting is captured as a relationship because you cannot have a sighting unless you have something that has been sighted.

  • What was sighted, such as the malware, campaign, or other SDO
  • Who sighted it and/or where it was sighted, represented as an identity
  • What was seen on systems and networks, represented as observed data

  • Define indicator sightings
    Define sightings that denote that an indicator was seen.

  • Define object sightings
    Define object sighting that describes that an object (malware, tool, threat actor, and so on) was seen.

Parent Topic:IoC Repository

Related topics

Attack modes and methods

Indicators of compromise

Observables

Attack patterns

Campaigns

Course of actions

Identities

Infrastructure

Intrusion set

Locations

Malware

Malware analysis

Observed data

Threat actors

Threat groupings

Marking definitions

Threat notes

Threat opinions

Threat reports

Tools

Vulnerabilities

Relationships

STIX Visualizer