Current ThreatQ Version Filter
 

About Exploratory Data Points

THREATQ REQUIRED PERMISSIONS

Default ThreatQ Role: Administrative, Maintenance, or Primary Contributor
Custom Role - Action Permissions: Artifact Management - Investigations

Exploratory Data Points are object nodes that have not been committed to an investigation.  These nodes can be an individual object you have added to your investigation or related to another object in the investigation. 

All objects begin as Exploratory Data Points until they have been committed to the investigation.  Objects can be committed to an investigation by right-clicking on the object's node and selecting Commit to Investigation.

Showing/Hiding Exploratory Data Points for an Investigation

This option sets the visibility configuration for the entire investigation.  You will not be able to show uncommitted object nodes on the Evidence Board if this option is not selected.  

  1. Click on any empty space on the Evidence Board to load the Investigation in the Action Panel.
  2. Scroll to the bottom of the Action Panel and check/uncheck the Show Exploratory Data Points option.

    Action Panel