WEBVTT 1 00:00:11.511 --> 00:00:17.917 Expirations allow you to deprecate stale intelligence based on a set of defined criteria. 2 00:00:19.019 --> 00:00:27.761 The expiration status should be used when an indicator is deemed by an analysts to pose less of a threat to their infrastructure than other indicators. 3 00:00:28.962 --> 00:00:33.800 Expiring an indicator relieves the data burden on your team or infrastructure. 4 00:00:35.168 --> 00:00:43.576 The expire status should when an indicator is deemed by an analyst to pose less of a threat to their infrastructure than others. 5 00:00:44.677 --> 00:00:51.418 You can manually change the expiration date for an individual indicator or multiple indicators in the ThreatQ application. 6 00:00:52.118 --> 00:00:59.559 You can also set an automatic expiration policy which allows you depreciate stall intelligence as the data becomes less relevant. 7 00:01:00.960 --> 00:01:07.400 You can manually change the status of an individual indicator to expired by navigating to its details page. 8 00:01:08.234 --> 00:01:11.037 Click on the status dropdown and select Expired. 9 00:01:14.841 --> 00:01:18.411 The Expires field will now read as Expired Today. 10 00:01:19.245 --> 00:01:24.017 You can perform the same steps to change an expired indicator to active or any other status. 11 00:01:26.352 --> 00:01:35.028 You can perform a bulk action status change the status of a set of indicators to expired using the advanced search function of the Threat Library. 12 00:01:36.296 --> 00:01:37.730 Perform an advanced search. 13 00:01:43.336 --> 00:01:47.874 Click on the Actions dropdown and select All Indicators under the Bulk Changes heading. 14 00:01:49.042 --> 00:01:53.847 Select expired for the new status of the indicators on the Bulk Changes page. 15 00:01:55.115 --> 00:02:01.454 ou can also use this process to change the status of expired indicators to active or any other available system status. 16 00:02:02.155 --> 00:02:03.690 Click on Apply Changes. 17 00:02:04.457 --> 00:02:09.596 The platform will inform you that the bulk action is now queued and when it has completed. 18 00:02:12.499 --> 00:02:20.473 The next methods we will cover will show you have to set expiration dates and policies which automatically control the expiration status. 19 00:02:21.541 --> 00:02:25.612 Use the following steps to set an individual indicator's expiration. 20 00:02:26.479 --> 00:02:30.550 Navigate to an indicator's details page within the ThreatQ platform. 21 00:02:31.351 --> 00:02:37.657 You will see an Add Expiration Date link next to the Expires field located at the top of the page. 22 00:02:38.191 --> 00:02:43.930 Note, if the indicators expiration date has already been set, you will see an extend link instead. 23 00:02:44.797 --> 00:02:47.066 Click on the Add Expiration Date and select 24 00:02:47.600 --> 00:02:48.735 Add Seven Days 25 00:02:49.269 --> 00:02:50.436 Add Fourteen Days 26 00:02:51.037 --> 00:02:53.106 And protect for auto-expiration. 27 00:02:53.473 --> 00:02:58.912 This will prevent an automated expiration policy or bulk action from expiring the indicator. 28 00:02:59.946 --> 00:03:02.916 The new expiration date will appear next to the expired field. 29 00:03:03.783 --> 00:03:07.787 Click on the extend link again to update or remove the expiration setting. 30 00:03:10.323 --> 00:03:14.260 Use the following steps to perform a bulk action expiration update. 31 00:03:15.061 --> 00:03:19.899 Perform a search in the ThreatQ Threat Library to select the indicators to update. 32 00:03:21.634 --> 00:03:26.639 Click on the Actions dropdown and select All Indicators under the Bulk Changes heading. 33 00:03:27.240 --> 00:03:29.909 Select the type of change for the expiration date. 34 00:03:30.343 --> 00:03:31.411 Optons include 35 00:03:31.778 --> 00:03:33.279 Extend Expiration Date 36 00:03:33.846 --> 00:03:35.548 Protect for Auto-Expiration 37 00:03:36.216 --> 00:03:37.684 Remove the expiration date 38 00:03:38.218 --> 00:03:39.786 And set a new expiration date 39 00:03:40.553 --> 00:03:47.694 Note, indicators that already have the protect from auto-expiration policy applied will not be affected by a bulk action. 40 00:03:53.533 --> 00:03:55.034 Click on Apply Changes. 41 00:03:58.238 --> 00:04:02.709 The platform will inform you that the bulk action is now queued and when it has completed. 42 00:04:03.843 --> 00:04:07.647 Use the following steps to set an automatic expiration policy. 43 00:04:07.880 --> 00:04:13.720 Click on the Threat Library option and select Indicator Expiration under the Data Controls heading. 44 00:04:14.254 --> 00:04:18.524 The page will load with the indicator expiration tab loaded by default. 45 00:04:19.626 --> 00:04:25.131 Locate the source that will receive the policy by either scrolling down the page or using the search filter 46 00:04:27.200 --> 00:04:30.570 Select a policy from the dropdown menu provided for the source. 47 00:04:30.870 --> 00:04:31.804 Options include 48 00:04:32.538 --> 00:04:39.646 Don't Automatically Expire. This is the application default. This prevents an automatic policy from expiring an indicator. 49 00:04:40.413 --> 00:04:44.417 The never expire indicators option prevents an indicator from ever expiring. 50 00:04:45.351 --> 00:04:47.453 And Automatically Expire Indicators. 51 00:04:47.820 --> 00:04:53.326 You can set a specific amount of days after ingestion, that once reached, will expire the indicator. 52 00:04:53.993 --> 00:04:58.765 You can also add exceptions to the policy by clicking on Exceptions to reveal the exceptions form. 53 00:04:59.932 --> 00:05:01.100 Click on Add Exception. 54 00:05:01.534 --> 00:05:08.775 Select the exception criteria and select the specific amount of days, after ingestion, that once reached, will expire the indicator. 55 00:05:09.275 --> 00:05:11.577 Click on Apply to save the changes. 56 00:05:13.179 --> 00:05:15.882 In this video, we covered expirations. 57 00:05:16.516 --> 00:05:21.788 You learned how to set an expiration status for an individual indicator and for a set of indicators. 58 00:05:22.855 --> 00:05:27.260 We also covered setting expiration dates and automatic expiration policies. 59 00:05:28.227 --> 00:05:32.298 See the Help Center for information on expirations and the ThreatQ platform.