About Relationships Panes
Default ThreatQ Role: Administrative, Maintenance, or Primary Contributor
Custom Role - Action Permissions: Objects & Context - Individual Object Context & Actions - Relationships
The Relationships section on an object's details page displays other ThreatQ system objects that are related to the current object. This section enables analysts to view relationship context, manage existing relationships, and navigate between connected objects.
From the Relationships section, you can:
-
Create or remove relationships between system objects.
-
Perform bulk updates for related indicators.
-
Customize the columns displayed for each related object type.
-
Open the details page for any related object by selecting it.
-
Access additional actions for supported related object types, such as indicators.
Investigations cannot be added as related objects.
Add a Relationship
If a relationship pane is not already displayed for an object type, create the initial relationship using Actions > Add Relationship.
To add a relationship:
-
Navigate to the appropriate related object section on the object's details page.
-
Select the Link icon.
-
In the Add Relationships dialog, add one or more objects by:
-
Searching for an existing object and selecting it from the results.
-
Entering the name of a new object and selecting Create to add it to the Threat Library.
-
-
Select Add to create the relationship.
Remove a Relationship
To remove one or more relationships:
-
Navigate to the appropriate related object section.
-
Select the checkbox next to each relationship to remove.
-
Select the Unlink icon.
Customize Displayed Columns
You can customize the columns displayed for each related object type (except Files) to show the information most relevant to your workflow.
To modify the displayed columns:
-
Navigate to the desired related object section.
-
Select the Columns icon.
-
Search for or browse the available columns.
-
Select or clear the corresponding checkboxes to show or hide columns.
ThreatQ provides default and required columns for each object type. Default columns can be hidden, while required columns are always displayed.
| Object Type | Default Columns | Required Columns |
|---|---|---|
| Adversaries |
|
|
| Assets |
|
|
| Attack Pattern |
|
|
| Campaign |
|
|
| Course of Action |
|
|
| Events |
|
|
| Exploit Target |
|
|
| Files |
|
|
| Identity |
|
|
| Incident |
|
|
| Indicators |
|
|
| Intrusion Set |
|
|
| Malware |
|
|
| Report |
|
|
| Signatures |
|
|
| Tasks |
|
|
| Tool |
|
|
| TTP |
|
|
| Vulnerability |
|
For Maintenance and Admin users, column selections are saved per user and applied to all objects of the same type. Read Only and Primary Contributor users can customize their current view; however, their column selections are not persisted.