About ThreatQ Orchestrator
Default ThreatQ Role: Administrative or Maintenance
Custom Role - Action Permissions: See the TQO Requirements topic.
ThreatQ TDR Orchestrator includes enhanced automation, analysis and reporting capabilities that accelerate threat detection and response across disparate systems.
Using Configuration-Driven Workflows (CDWs), applying Smart Collections, and Custom Scoring, ThreatQ prioritizes the threats that are important for remediation. That could be simple automation to quarantine the device or more complicated workflows to remediate the threat by shutting down a service, removing malware, restoring the system, submitting an alert, creating a ticket or initiating an investigation.
ThreatQ TDR Orchestrator can involve any number of tools and should provide cross team visibility for a more complete XDR security solution.
Data-Driven Triggers
Define what type of data to enrich using the ThreatQ Threat Library. Save your Threat Library queries as Data Collections to be used as Data-Driven Triggers in the orchestration workflow.
Configuration-Driven Workflows (CDWs)
CDWs, also known as Data-Driven Playbooks, take your identified triggers, in the form of Data Collections, and enrich your selected threat intelligence data using third-party providers such as Shodan, to curate further detailed threat information.
TQO gives you the option to import advanced workflows from predefined YAML files or create your own workflows in the TQO workflow builder.
Capture Enriched Data
The enriched information captured by the CDW is then ingested back into the ThreatQ platform for further analysis and refinement.
PDF User Guides
TQO is a part of the ThreatQ platform and receives its updates with the platform upgrades. The version numbers assigned to the PDF guides below are for document tracking purposes. Use the TQ Platform Version column to select the correct TQO user guide.
User Guide | TQ Platform Version | Publication Date |
---|---|---|
ThreatQ TDR Orchestrator Guide v2.5.0 | >=6.8.0 | 2025-04-30 |
ThreatQ TDR Orchestrator Guide v2.4.0 | 6.7.0 - 6.7.4 | 2025-01-28 |
ThreatQ TDR Orchestrator Guide v2.3.0 | 6.3.0 - 6.6.0 | 2024-09-17 |
ThreatQ TDR Orchestrator Guide v2.2.0 | 5.29.1 - 5.29.4 | 2024-05-16 |
ThreatQ TDR Orchestrator Guide v2.1.0 | 5.17.0 - 5.29.0 | 2023-07-20 |
ThreatQ TDR Orchestrator Guide v2.0.0 | 5.16.0 | 2023-06-21 |
ThreatQ TDR Orchestrator Guide v1.4.0 | 5.15.0 | 2023-04-27 |
ThreatQ TDR Orchestrator Guide v1.3.0 | 5.14.0 | 2023-04-27 |
ThreatQ TDR Orchestrator Guide v1.2.0 | 5.12.0 - 5.13.0 | 2023-02-23 |
ThreatQ TDR Orchestrator Guide v1.1.0 | 5.8.0 - 5.11.0 | 2022-12-01 |
ThreatQ TDR Orchestrator Guide v1.0.0 | 5.6.0 - 5.7.0 | 2022-10-19 |