The Description Attribute, found on every Indicator, Group, Tag, Track, Victim, and Victim Asset in ThreatConnect®, is a space for the analyst to provide a brief, high-level explanation of the nature of the content. This information is useful for future reference and to enable team members to quickly comprehend the meaning of the threat intelligence that they are seeing.
Viewing, Creating, Editing, and Deleting Descriptions
- From the top navigation bar (Figure 1), hover the cursor over Browse and then over the Indicators, Groups, Tags, Tracks, Victims, or Victim Assets option. Click on one of the objects (Host Indicator in this example) to display a results table (Figure 2).
- Click on one of the entries, and the Details drawer for that entry will be displayed (Figure 3).
- Click the Details icon at the top right corner of the drawer, and the Overview tab of the Details screen will be displayed (Figure 4). Alternatively, hover over the object's entry in the table in Figure 2 and click on the Details icon that appears on the right side of its Summary cell to go straight to the Overview tab of the Details screen. Scroll down until the Description card appears on the left.
- Figure 5 is an example of a Description for an Indicator involving virtual private networks (VPNs). The goal of a good Description is to provide information on who, when, where, how, and why in a succinct manner. When possible, answer these questions in the Description card, and reserve in-depth analysis for the "Additional Analysis and Context" Attribute. See Creating Attributes for more information.
- To enter a new Description, click on the Click here to add one. text in the Description card (Figure 6).
NOTE: The Description card for Tags and Tracks is different from the one in Figure 6. To enter a new Description for these objects, click on the Click here to enter a Description text in the Description card, and then click the checkmark icon. To edit an existing Description, click on it, enter new text or edit the existing text, and then click the checkmark icon.
- The Edit Attribute window will be displayed (Figure 7).
- Attribute Type: Select Description from the dropdown menu at the top of the screen.
- Default: Check this box to set this Description as the default in the event that there are other Descriptions for the object from other sources.
- Choose Security Labels: Choose a Security Label for the Description.
- Attribute Source: Choose an existing Attribute Source from the dropdown menu or enter a new one.
- Save Source: Click this checkbox to save the Source so it will appear in the Attribute Source dropdown menu in the future for objects belonging to the same owner.
- Text Box: Click inside the text box to enter the Description, either in plain text or in Markdown. (See the "Using Markdown with an Attribute" section in Creating Attributes.)