Threat Entities.
A Threat Entity is a Threat Actor, a piece of malware, or a vulnerability. Each one has a single canonical record that the platform maintains: deduplicated, with its aliases merged, its description written from the reporting, and kept current as new reporting lands.
These records are global. You do not build your own copy of APT35, and there is no version of it that is yours alone. Your Threat Library shows you the catalog, and the entities that appear in your reporting surface there already described. That is rather the point: the work of assembling a profile has already been done.
Aliases
The same actor is named differently by everyone who reports on it, and that fragmentation is one of the more tedious problems in threat intelligence. Aliases are merged into one record, so APT35 and Charming Kitten are one entity with one profile rather than two half-complete ones you have to reconcile.
What an entity card holds
The card opens with the name and aliases, then the description, which usually begins with a Latest Developments paragraph covering what has changed since the profile was last written.
For Threat Actors you also get the origin attributed to them and the sectors and countries they target. Vulnerabilities carry their CVE identifier and severity scoring.
ATT&CK techniques
The techniques panel is drawn from reporting rather than from a static catalog. A technique appears because a report documented this actor using it, and each technique shows when it was first and last observed, along with the Threat Events that observed it and the dates they did.
That grounding has a consequence worth stating plainly: some actors show few techniques, or none at all. This is not a gap in the data. It means little has actually been documented, and an honest empty list is more useful than a plausible-looking one assembled from association.
Relevance to your organization
Every entity card carries a Relevance to your organization assessment: what this actor, malware family, or vulnerability means for you specifically, written from your organizations' sectors, countries, watched regions, technologies, and suppliers.
This is generated automatically when you open the card, so there is nothing to click. While it is being written or refreshed the card shows that it is analysing, then fills in, and it carries the date it was last analysed so you know how current it is.
Because this analysis is specific to you rather than to the entity, it is processed in the region assigned to your account. See Data hosting and regions.
Linked reporting
At the bottom of the card you find the reporting linked to this entity. To report on it, select the events you want to include and click Report on Selected, then pick one or more Organizations, choose the chapters to include, and optionally point the report at a specific Intelligence Requirement to focus it. See Report on a Threat Entity or requirement.
Frequently asked questions
What types of Threat Entity are there?
Three: Threat Actors, malware, and vulnerabilities. Each has a single canonical record shared across the platform, with its aliases merged into it.
Do I have to create the entities I want to track?
No. Threat Entities come from a global catalog the platform maintains and keeps current. They appear in your Threat Library already described, rather than being records you build yourself.
Why do some Threat Actors show only a few techniques?
Techniques are drawn from actual reporting rather than a static catalog, so an actor shows the techniques that have genuinely been observed and dated. A short list means little has been documented, which is itself worth knowing.