About Indicators
Default ThreatQ Role: Administrative, Maintenance, or Primary Contributor
Custom Role - Action Permissions: Objects & Context - Objects, Individual Object Context & Actions
Note: If a user has View Only permission for Sources, system object creation modals default to the user’s login as the object source.
An Indicators is information that describes or identifies methods used to defeat security controls, exploit vulnerabilities, and gain unauthorized access to an internal network. Indicators can also describe malicious reconnaissance to gather technical information, malicious cyber command and control, and any other attribute of cyber security whose disclosure is prohibited by law.
Indicators can be scored to allow you to apply weighting using contextual information, such as sources, attributes, and indicator types, as they are added to ThreatQ. You can also set a manual score per indicator.
You can also apply expiration dates to an indicator to when it is determined to pose less of a threat to your infrastructure than other indicators.
Adding an Indicator
- Click on Create > Indicator.
The Add Indicators window is displayed.
- Enter a value in the Value field.
- Select the Type of Indicator.
- Select a Source from the provided dropdown list.
You can also click the Add a New Source option if the desired source is not listed in the drop-down list. If administrators have enabled TLP view settings, you can select a TLP label for the new source in the dropdown list provided. See the Traffic Light Protocol (TLP) topic for more information on TLP schema.
- Select a Status for the indicator.
- Select any Related Objects you need to link to the indicator. This field is optional.
- Click Add Indicator.
Adding Context
See the About Object Details section and its topics for details on adding context to an object such as adding sources, attributes, and related objects.
Editing Indicators
- Locate and click on the indicator.
The Indicator Details page opens.
- Click on Edit next to the Indicator name.
The Edit Indicator dialog box opens.
- Make the desired change to the indicator Value and Type.
- Click on Save Indicator.
Deleting an Indicator
- Locate and click on the Indicator.
The Indicator Details page opens.
- Click on Delete this Indicator located to the top right of the page.
A confirmation dialog box appears.
- Click on Delete Indicator.