Exporting Investigations as Threat Model Entities

Investigations can be exported as new threat models or added to existing threat models for wider distribution with the ThreatStream community.

When you export an investigation, all attachments and associated entities are included in the resulting threat model entity. Files attached to analysis are not included. After export, the resulting threat model is added to the investigation as an association.

Additionally, an import session is initiated for any observables listed in the investigation as Not Imported Observables. The TLP color assigned to the investigation is automatically applied to the import session.

Exporting Investigations as New Threat Model Entities

Investigations can be exported as new Actors, Attack Patterns, Campaigns, Courses of Action, Identities, Incidents, Infrastructure, Intrusion Sets, Malware, Threat Bulletins, Tools, TTPs, or Vulnerabilities.

To export an investigation as a threat model:

  1. Navigate to the investigation which you want to export.
  2. Select Export to Threat Model from the Export menu.

  3. Under Choose Threat Model Type, select a threat model type.

  4. Confirm the Title, TLP, Tags, Visibility, and Description.
  5. If you want to include the MITRE ATT&CK Framework matrix from the investigation to the exported threat model, select Add Current MITRE Table Image to Description. A static image of the matrix in its current state will be added to the description of the resulting threat model. The image is a non-interactive, point in time snapshot.

    For more on the MITRE ATT&CK Framework, see Using the MITRE ATT&CK Framework in Investigations.

  6. Click Save.

    Note: Any unsaved work in the investigation is automatically saved upon export.

Exporting Investigations to Existing Threat Models

You can add investigation entities to already existing threat models which you are allowed to edit.

To export an investigation to an existing threat model:

  1. Navigate to the investigation which you want to export.
  2. Select Export to Threat Model from the Export menu.
  3. Click Existing Threat Model.
  4. In the Search Existing Threat Models field, enter a threat model name to which you want to export investigation entities.

  5. Select the threat model of your interest from the search results. The selected threat model appears under the Search threat models bar.
  6. Click Save.

The investigation entities are added to the threat model.

Note: Only entities that are not associated with the selected threat models are added. Duplicates are skipped.