Approving Import Jobs

Observables extracted from import jobs must be approved before they can become part of your threat intelligence.

Note: Only users with Approve Intel privileges can approve import jobs for their organization.

Import jobs can be approved from Import Job Details pages or in bulk from the Import page.

Reviewing and Approving a Single Import Job

Approving Import Jobs in Bulk

Reviewing and Approving a Single Import Job

When you approve an import job, all observables in the Included tab are added to your threat intelligence and made active. Observables in the Excluded tab will not be added. See Managing Excluded Observables for possible actions that can be taken on excluded observables, such as force-adding and removing excluded observables.

Note: If you do not have the privileges to approve an import job, you cannot approve import jobs, but you can send a request to your organization administrator to review a specific job. Additionally, you can edit the import jobs you submit. See Managing Import Jobs for more information.

To approve an import job:

  1. Navigate to ThreatStream > Manage > Imports.
  2. Click the job in the Ready To Review status that you want to approve. The Import Job Details page is displayed. If you have the privileges to approve import jobs, the page displays the Approve and Reject buttons at the right top corner of the page.
    By default, the table with observables displays the Observables, iType, Confidence, and Status columns. To see other columns such as Type, Expiration Date, Country, Classification, Organization, Source Created, Source Modified, and Notes, click the Table Settings gear and select the columns you want to be displayed. Additionally, you can change the order of columns in the table by using the drag-and-drop functionality, specify the number of rows to be displayed per page, and enable/disable horizontal scrolling.

  3. (Optional) In the Anonymize section in the Included tab, select User and Organization if you want to anonymize your user and organization information. Users outside of your organization with access to the observables will see "Analyst" in all the fields that would otherwise display on organization or user name.

  4. (Optional) Click Edit to configure the included observables of the import job:
    • Visibility: Visibility assigned to tags that you want to associate with imported observables. Tags assigned the My Organization visibility setting are only visible to your organization. Tags assigned the Anomali Community visibility setting are visible to users of all organizations that have access to the observable. To add a tag, select a Visibility setting, enter the tag, and click the plus icon. Tags can contain spaces. Tags will be associated with each observable included in the import job.
    • Intelligence Source: Add a meaningful label about the source from which the observables were obtained.

    • TLP: Add the TLP color to associate with the job.

    • Comments: Comments will be associated with each observable included in the import job.

    • Tags: To add private tags that are only visible to your organization, assign them the My Organizationvisibility setting. Tags assigned the Anomali Communityvisibility setting are visible to any user with access to the observable. See Adding Private Tags to Observables for more information.

    • Expiration Date: Edit the expiration date for all observables included in the import session.

    • Intelligence Initiative: Click Add Intelligence Initiative to associate an intelligence initiative with the observable in the import job. For more information about intelligence initiatives, see Attributing Organizational Goals with Intelligence Initiatives.

    • Source Locations: Add or remove source locations. ThreatStream supports 325 geographical locations (as defined by STIX 2.1) including 27 regions, 247 countries, 50 US States, and Washington DC.

    • Target Locations:  Add or remove target locations. ThreatStream supports 325 geographical locations (as defined by STIX 2.1) including 27 regions, 247 countries, 50 US States, and Washington DC.

    • Target Industry: Add or remove target industries. Target industries available for selection are defined by the STIX 2.1 Industry Sector vocabulary.

    • Associated With: Associate the imported observables with threat model entities.

  5. Review the observables listed as Included and make any necessary changes. You can filter included observables by Type, Indicator Type, or Confidence by clicking the filter icon. Click Reset to remove filter conditions.

You can take the following actions on Included observables:

  • Exclude: Move the selected included observables to the excluded tab. See Managing Excluded Observables for more information.

  • Edit: Modify the indicator type mapping, expiration date, or confidence score of the selected observables.

Additionally, you can edit the values of included observables by clicking the edit icon corresponding to the value you want to edit.

See Editing Observable Values Before Approval for more information.

  1. Review the observables listed under the Excluded tab and make the necessary changes.

    Note: Click the filter icon to filter observables by Type, iType, and Confidence.

    When you click the Excluded tab, the table with all observables excluded from the import job is displayed. By default, the table displays the Observables, iType, and Confidence columns. To see other columns such as Type, Country, Classification, and Organization, click the Table Settings gear and select the columns you want to be displayed. You can also change the number of rows to be displayed on the page.

    When selected, the following actions can be taken with excluded observables:

    Additionally, you can edit the values and indicator types of Excluded observables by clicking the edit icon corresponding to the observable you want to edit.

    See Editing Observable Values Before Approval for more information.

  2. (Optional) Add additional observables to the import job by clicking New.

    You can add up to 10 observables at once. You must select an indicator type (iType) for each value.

    Click Add Observables. The new observables are scored by ThreatStream and added to the import job.

  3. To approve the import job and add included observables to your threat intelligence, click Approve.

When all observables listed in the Included tab are approved they become part of your threat intelligence on ThreatStream.

Approved imports can be viewed on the Import page.

Note: Observables assigned a confidence score of 15 or below are made private to your organization, regardless of the visibility setting you selected for the import job.

Approving Import Jobs in Bulk

Users with the Approve Intel privilege can approve or reject import jobs in bulk from the Imports page. When you approve import jobs in bulk, observables listed in the Included tabs of the selected import sessions immediately become active. Therefore, you must ensure that all import jobs have been adequately reviewed before executing bulk approval.

To approve import jobs in bulk:

  1. Navigate to ThreatStream > Manage > Imports.
  2. Select the import jobs in the Ready To Review status that you want to approve.
  3. Click Approve in the top right corner of the table.

The page will refresh when ThreatStream finishes processing your request. The status for the import jobs changes to Approved.

Note: Only users with the Approve Intel privileges can approve import jobs in bulk. Users without the privilege cannot send bulk approval requests.