Your Threat Library.
Your Threat Library is where the Threat Actors, malware, and vulnerabilities live. It is a maintained catalogue, and it is already populated. You open an entity and the profile is there: aliases merged, description written from the reporting, techniques dated to the reports that observed them, and an assessment of what it means for you.
Finding what matters to you
Two routes cover most of it.
- Open a report and click through any of the entities linked to it. These are the threats actually appearing in your reporting, which makes them the natural place to start.
- Search the Threat Library directly when you have a specific actor, malware family, or CVE in mind.
What you get on an entity
Every entity shows the same things: the aliases it is known by, a description that opens with what has changed most recently, the ATT&CK techniques observed in reporting with the dates they were seen and a note on how each was used, and a Relevance to your organization assessment written from your sectors, countries, technologies, and suppliers. That last one is generated for you automatically when you open the entity.
Making your library deeper
The identity of an entity is shared across the platform, but the evidence attached to it is yours. The reporting, indicators, and observed techniques you can see on an actor are the ones your sources entitle you to, so the Threat Library gets richer as you connect more Modules, bring in licensed feeds, and upload your own research. See Threat Entities for how that works.
Where your threats show up
Entities surface across the platform, including on your Recent Threats dashboard, where they are highlighted on any Event that mentions them, and on the Threat Events they have been observed in.
To report on one, see Report on a Threat Entity or requirement.
Frequently asked questions
How do I find the threats that matter to me?
Open the entities that appear in your own reporting, or search the Threat Library directly. Every entity carries an assessment of what that threat means for your organizations specifically.
What is already there when I open an entity?
The aliases it is known by, a description opening with what has changed most recently, the ATT&CK techniques observed in reporting with the dates they were seen and how each was used, and a relevance assessment written for your organizations.
Can I make an entity's profile richer?
Yes, by adding sources. The reporting, indicators, and observed techniques on an entity are the ones your sources entitle you to see, so every feed you turn on and every report you upload deepens the profiles of the adversaries you care about.