Creating Intelligence Initiatives

Org Admins can create intelligence initiatives from the Intelligence Initiatives screen.

To create an intelligence initiative:

  1. Navigate to ThreatStream > ManageIntelligence Initiatives. The intelligence initiatives screen is displayed.

  2. Select New Initiative from the Actions menu, or click + Add Initiative.


  3. Select the type of intelligence initiative you want to create. You can select Adversary Monitoring, Brand Monitoring, Domain Monitoring, Fraudulent Activity, Geopolitical, Malware Intelligence, Mobile, Phishing, Physical Infrastructure, Social Media, Threat and Risk Analysis, and Vulnerability and Patch Management.

    Note: Only types which are not associated with open initiatives are displayed. You can only have one active initiative of a given type at once.

  4. Select a Start Date and End Date to specify a time period for the initiative. Time periods can be no longer than 180 days.

  5. Click Save Changes to create the initiative.

  6. To associate Collections (feeds) with the initiative:

    1. On the Collections tab of the initiative, click Add Feed above the Collections table settings.

    2. Select the feeds of interest and click Add.

      Note: You can add a maximum of 100 feeds to an intelligence initiative.

  7. To associate Investigations with the initiative:

    1. Navigate to ResearchInvestigations.

    2. Locate the investigation of interest and click the investigation name to open the details page of the investigation.

    3. Under Intelligence Initiatives, select the intelligence initiative type associated with the initiative of interest. You can select multiple intelligence initiatives for the investigation.

  8. To associate rules with the initiative:

    1. Navigate to ManageRules.

    2. Select the rule you want to associate with the initiative.
    3. Click Edit.
    4. Under Intelligence Initiatives, select the intelligence initiative type associated with the initiative of interest. You can select multiple intelligence initiatives for the rule.

  9. To associate sandbox detonations with the initiative:

    1. Navigate to the details page of the sandbox detonation you want to associate with the intelligence initiative. See Viewing Sandbox Reports for more information.

    2. Click Add Intelligence Initiative.

    3. Select the intelligence initiative with which you want to associate the detonation.

    4. Click Add.

    Note: You can also associate sandbox detonations with intelligence initiatives during the submission process. Click Add Intelligence Initiative under Intelligence Initiative on the Analyze in Sandbox window before submitting your detonation. See Submitting Malware for Detonation for more information.

  10. To associate import sessions with the initiative:

    1. Navigate to the Import Review page of the import session you want to associate with the initiative. See Viewing Import Jobs Associated With Your Organization for more information.

    2. Click Add Intelligence Initiative.

    3. Select the intelligence initiative with which you want to associate the import session.

    4. Click Add.

    Note: You can also associate import sessions with intelligence initiatives during the import process. Click Add Intelligence Initiative under Attribute to Intelligence Initiative on the import assistant before submitting your import. See Importing Observables for more information.

  11. To associate Threat Model entities with the initiative:

    1. Open the Threat Models tab of the intelligence initiative.

    2. To associate threat model entities using a saved search, select Saved Searches under Attribution Source and then click Add Saved Search. Select the saved search of interest and then click Save Change. Threat Model entities returned by the saved search and modified within the time period specified for the intelligence initiative are listed in the Threat Model table. For more information on creating saved advanced threat model searches, see Saving Threat Model Search Filters.

      To manually associate threat model entities with the initiative, navigate to the details page of the threat model entity you want to associate and select the intelligence initiative under Intelligence Initiatives. You can select multiple intelligence initiatives.

      Note: Threat model entities can only be manually associated with intelligence requirements from the details page of the threat model entities. Saved search attribution configured for the primary intelligence initiative does not apply to associated intelligence requirements.

  12. To associate observables with the initiative:

    1. Open the Observables tab of the intelligence initiative.

    2. To associate observables using a saved search, select Saved Searches under Attribution Source and then click Add Saved Search. Select the saved search of interest and then click Save Change. Observables returned by the saved search and modified within the time period specified for the intelligence initiative are listed in the Observables table. For more information on creating saved advanced observables searches, see Saving Threat Model Search Filters.

      To manually associate observables with the initiative, navigate to the details page of the observable you want to associate and select the intelligence initiative under Intelligence Initiatives in the Intelligence table. You can select multiple intelligence initiatives.

      Note: Observables must be manually associated with intelligence requirements from the details page of the observables. Saved search attribution configured for the primary intelligence initiative does not apply to associated intelligence requirements.