Collections.
A Collection groups related Threat Entities into one bucket around a topic you want to track as a whole, like ransomware operators from Russia, threat actors from Iran, or every infostealer you know of. When you create one, Liberty91 explores the topic, finds or creates the relevant entities, links them together, and writes a combined description and analysis, so you get a clustered view and the reporting behind it in one place.
How to create a Collection
Go to Collections under your Threat Library and click Create New Collection at the top. Give it a name, and the platform builds the cluster for you.
When you create a Collection, Liberty91 runs an initial exploration of the topic against your sources, drawing on everything it knows. For ransomware operators from Russia, for example, it explores the topic, identifies the relevant Threat Actors, malware, and vulnerabilities, then finds the matching cards in your Threat Library or creates them where they do not yet exist. It links every entity to the Collection and writes a description and analysis of the Collection as a whole from the reporting on those linked cards.
The Collection page
Description
The page shows the description and analysis at the top. Click Update Description to refresh it when it feels outdated. You can also set a criticality rating, which tells the platform how important this Collection is to you.
Threat Library links
On the right you see the Threat Library links: every Threat Actor, malware, vulnerability, and even other Collections linked to this one. You can add or remove links by hand.
Linked reporting
At the bottom you find all the relevant reporting, the Events linked to any card in the Collection. These are pulled together for the Collection and form the basis for its description and analysis.
To report on the topic, select one or more of these Events and click Report on Selected. See Report on a Threat Entity or requirement for the full reporting flow.
Frequently asked questions
What is a Collection?
A Collection groups related Threat Entities, such as Threat Actors, malware, and vulnerabilities, into one bucket around a topic like ransomware from Russia or infostealers.
What happens when I create a Collection?
Liberty91 explores the topic against your sources, finds or creates the relevant Threat Entities, links them to the Collection, and writes a combined description and analysis from their reporting.