Current ThreatQ Version Filter

About Relationships Panes

THREATQ REQUIRED PERMISSIONS

Default ThreatQ Role: Administrative, Maintenance, or Primary Contributor
Custom Role - Action Permissions: Objects & Context - Individual Object Context & Actions - Relationships

The Relationships section on an object's details page displays other ThreatQ system objects that are related to the current object. This section enables analysts to view relationship context, manage existing relationships, and navigate between connected objects.

From the Relationships section, you can:

  • Create or remove relationships between system objects.

  • Perform bulk updates for related indicators.

  • Customize the columns displayed for each related object type.

  • Open the details page for any related object by selecting it.

  • Access additional actions for supported related object types, such as indicators.

Investigations cannot be added as related objects.

Add a Relationship

If a relationship pane is not already displayed for an object type, create the initial relationship using Actions > Add Relationship.

To add a relationship:

  1. Navigate to the appropriate related object section on the object's details page.

  2. Select the Link icon.

  3. In the Add Relationships dialog, add one or more objects by:

    • Searching for an existing object and selecting it from the results.

    • Entering the name of a new object and selecting Create to add it to the Threat Library.

  4. Select Add to create the relationship.

Remove a Relationship

To remove one or more relationships:

  1. Navigate to the appropriate related object section.

  2. Select the checkbox next to each relationship to remove.

  3. Select the Unlink icon.

Customize Displayed Columns

You can customize the columns displayed for each related object type (except Files) to show the information most relevant to your workflow.

To modify the displayed columns:

  1. Navigate to the desired related object section.

  2. Select the Columns icon.

  3. Search for or browse the available columns.

  4. Select or clear the corresponding checkboxes to show or hide columns.

ThreatQ provides default and required columns for each object type. Default columns can be hidden, while required columns are always displayed.

Object Type Default Columns Required Columns
Adversaries  
  • Name
  • Date Created
  • Linked By
  • Confidence
  • Comments
Assets  
  • Value
  • Date Created
Attack Pattern  
  • Value
  • Date Created
Campaign  
  • Value
  • Date Created
Course of Action  
  • Value
  • Date Created
Events
  • Date Created
  • Type
  • Title
  • Date of Occurrence
Exploit Target  
  • Value
  • Date Created
Files  
  • Title
  • Sources
  • Date Added
Identity  
  • Value
  • Date Created
Incident  
  • Value
  • Date Created
Indicators
  • Score
  • Status
  • Value
  • Date Created
Intrusion Set  
  • Value
  • Date Created
Malware  
  • Value
  • Date Created
Report  
  • Value
  • Date Created
Signatures
  • Type
  • Date Created
  • Name
Tasks
  • Assigned To
  • Status
  • Priority
  • Name
  • ID
Tool  
  • Value
  • Date Created
TTP  
  • Value
  • Date Created
Vulnerability  
  • Value
  • Date Created

For Maintenance and Admin users, column selections are saved per user and applied to all objects of the same type. Read Only and Primary Contributor users can customize their current view; however, their column selections are not persisted.