Creating Content with Anomali Lens in ThreatStream

You can use Anomali Lens to create Threat Bulletins, Investigations, and Import Sessions from anywhere in the platform.

Note: Read Only users cannot create Threat Bulletins, Investigations, or Import Sessions through Anomali Lens in ThreatStream.

Creating Threat Bulletins from Anomali Lens

To create a Threat Bulletin from Anomali Lens:

  1. After scanning a page, click Create Threat Bulletin on the Lens window.
  2. Select the entities you want to include in the Threat Bulletin. You can also use the filters to select all entities of a particular highlight type.

    The number of selected entities is reflected in the Create Threat Bulletin button.

    Note: You can also create Threat Bulletins when no entities are detected by Anomali Lens.

  3. Click Create Threat Bulletin.

    The new Threat Bulletin has been created. You are redirected to the Threat Bulletin details page in edit view. See Editing Threat Bulletins for more information.

    If new observable values were included in the Threat Bulletin you created, an import session window is displayed.

    See Approving Import Jobs for more information.

    The entities you selected are automatically associated with the new Threat Bulletin.

Creating Investigations from Anomali Lens

To create an Investigation from Anomali Lens:

  1. After scanning a page, click Investigate on the Lens window.
  2. Select the entities you want to include in the Investigation. You can also use the filters to select all entities of a particular highlight type.

  3. Click Investigate.
  4. If you want to add the entities to an existing Investigation:

    1. Select Add to Investigation.
    2. Use the Search function to locate the Investigation of interest. You can also click Show Filters to filter Investigations by Last Modified date and Reporter.

    3. Select the Investigation of interest from the Results list.
    4. Click Add to Investigation.

    Lens displays the following message when it finishes adding the entities:

    Click View Investigation to view the updated investigation in ThreatStream.

    Note: ThreatStream may not complete grouping entities on the chart view of the Investigation if you attempt to open the Investigation before Lens displays this success message. If you close the Lens window before the success message is displayed, Lens sends you a browser notification, such as the following:


    Click View Details to view the Investigation.

    OR

    If you add the entities to a new Investigation:

    1. Select Create Investigation.

    2. Confirm the Investigation Name. The name of the scanned page is automatically populated.
    3. Select an Assignee for the Investigation.
    4. Click Create Investigation.

    When investigation creation is complete, Lens displays the following message:

    Click View Investigation to view the investigation in ThreatStream.

    Note: ThreatStream may not complete grouping entities on the chart view of the Investigation if you attempt to open the Investigation before Lens displays this success message. If you close the Lens window before the success message is displayed, Lens sends you a browser notification, such as the following:


    Click View Details to view the Investigation.

Creating Import Sessions from Anomali Lens

To create an import session from Anomali ThreatStream:

  1. After scanning a page in ThreatStream, click Import on the Lens window.
  2. Select the observables you want to import.

    Note: Select the Unknown filter to select all observables highlighted by Lens that are currently unknown to ThreatStream.

  3. Click Import.

You are redirected to the import review screen. See Approving Import Jobs for more information.