Your Threat Library.
Your Threat Library is where the Threat Actors, malware, and vulnerabilities live. The useful thing to know before you start is that there is nothing to build. It is a maintained catalog, shared across the platform, and it is already populated.
That is a change worth calling out if you have used other tools. There is no step where you create a record for an actor, name it, and wait for it to fill in. You open the entity and the profile is there: aliases merged, description written from the reporting, techniques dated to the reports that observed them, and an assessment of what it means for you.
Finding what matters to you
Two routes cover most of it.
- Open a report and click through any of the entities linked to it. These are the threats actually appearing in your reporting, which makes them the natural place to start.
- Search the Threat Library directly when you have a specific actor, malware family, or CVE in mind.
What you get on an entity
Every card carries the same things: the aliases the entity is known by, a description that opens with what has changed most recently, the ATT&CK techniques observed in reporting with the dates they were seen, and a Relevance to your organization assessment written from your sectors, countries, technologies, and suppliers.
That last one is generated for you automatically when you open the card. See Threat Entities for what each part of the card means.
Where your threats show up
Entities surface across the platform, including on your Recent Threats dashboard, where they are highlighted on any Event that mentions them, and on the Threat Events they have been observed in.
To report on one, see Report on a Threat Entity or requirement.
Frequently asked questions
Do I have to add threats one by one?
No. The Threat Library is a maintained catalog rather than a list you assemble. Threat Actors, malware, and vulnerabilities are already there, already described, and already updated as new reporting lands.
How do I find the threats that matter to me?
Open the entities that appear in your own reporting, or search the catalog directly. Every card carries an assessment of what that threat means for your organizations specifically.