Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Threat Intelligence administration

The Threat Intelligence base system is ready to use on activation. You can add records to certain modules in the Administration application menu, but most are already populated with industry-standard information.

The following applications are available under the Administration module of the Threat Intelligence navigation bar:

ApplicationDescription
PropertiesThreat Intelligence properties allow you to control how different aspects of the system function, including the setting of API keys.
Attack MechanismsThis module organizes attack patterns hierarchically, based on mechanisms that are frequently employed when exploiting a vulnerability.
Attack MotivationsThis module lists the possible attack motivations that shape intensity of an attack by a threat actor or intrusion set.
Discovery MethodsThis module describes how security incidents are discovered.
FeedsThis feature has been deprecated.
Indicator TypesThis module is used to characterize cyber threat indicators made up of patterns that identify certain observable conditions, as well as contextual information about the meaning of the patterns, and how and when they are acted on.
Infrastructure TypesThis module lists the possible classifications of infrastructure.
Intended EffectsThis application is used for expressing the intended effect of a threat actor.
Malware CapabilitiesThis module lists the possible capabilities of malware.
Malware TypesThis module lists the possible classifications of malware.
NotificationsThis module is used for creating email notifications. This involves specifying when they are sent, who receives them, and what they contain.
Observable TypesThis module lists the possible classifications of an observable, such as an IP address or file hash.
Report TypesThis module lists the possible classifications of threat reports.
Threat Actor RolesThis module lists the roles the threat actors play.
Threat Actor TypesThis module characterizes malicious actors (or adversaries) representing a cyber attack threat, including presumed intent and historically observed behavior.
Threat Lookup Finding CalculatorsThis module calculates the findings based on the responses received. For third-party integrations that provide the computed results, the threat lookup finding calculator maps the results to supported findings in the system. For more information, see Threat Lookup Finding Calculators.
Tool TypesThis module lists the possible classification of tools.