Skip to content
Release: Australia · Updated: 2026-06-02 · Official documentation · View source

Automatic Threat Actor priority tagging

Learn how to enable automatic tagging of Threat Actors based on their origin locations.

Before you begin

Role required:

  • admin
  • sn_sec_tisc.admin

About this task

When a relationship between a Threat Actor and a Location object is created or updated, and the relationship type is originates-from, a Priority: Critical tag is automatically added to the Threat Actor.

Procedure

  1. Navigate to All > Threat Intelligence Security Center > Administration.

  2. Select Automated Flows.

  3. Select the Automatic Threat Actor priority tagging link to view the respective rule details in the flow designer.

  4. View the flow designer action for the following trigger:

    Object-Object Relationship Created or Updated where (Source Object Type is threat-actor, and Target Object Type is location, and Target Object . Name [Location] is one of China, North Korea, and Relationship Type is originates-from, and Source Object . TISC Tags [Threat Actor] does not contain Priority: Critical)
    
  5. If an Object-Object relationship is created or updated between a Threat Actor and a Location, and the relationship type is originates-from, add a Priority: Critical tag to the Threat Actor.

Image omitted: tisc-automatic-priority-tagging.png
Automatic Threat Actor priority tagging in TISC

Parent Topic:Working with automated flows

Related topics

Automated IOC Enrichment

Automated sharing of high-risk IOC's with trusted partners

Automatically add threat intelligence to a TAXII collection

Create vulnerability assessment for zero day

Analyze, assess, and disseminate observables

Analyze and assess threat IoC’s

Vulnerability Management Support

Zero-day vulnerability tracking

Automated flows tables