Searching Intelligence in ThreatStream

ThreatStream enables you to comb the multitude of intelligence available to you on ThreatStream, including Observables, Threat Bulletins, Actors, Campaigns, TTPs, Incidents, Signatures, Vulnerabilities, and Investigations.

The search box in the ThreatStream top navigation bar queries all available observables and threat model entities in a single search. Search queries are not case sensitive and results are returned regardless of case. For more on case sensitivity, see Case Sensitivity in ThreatStream Search.

For more details on searching observables only, including Basic and Advanced search functionality, see Searching for Observables in ThreatStream.

For more details on searching individual threat model entities only, see Accessing Threat Models.

For more details on investigations, see Investigating Threats in ThreatStream

Fields Queried in Universal Searches

Universal search queries observable values for observables and Aliases, Descriptions, Names, and Tags for threat model entities.

Universal Search Results Page

The universal search results page gives you an overview of the results for the entered keyword in each entity. Note that ThreatStream universal search does not return associations. To see associations with the intelligence containing the entered keyword, use the drill-down links to the observable details pages in the Indicator column.

(Click the image to enlarge it).

Observable search results. Only observables with the status Active are queried. To view a complete list of results on the ThreatStream Search page, click See more in Search for a complete list of results on the ThreatStreamSearch page.

Threat model entity search results. To view a complete list of results for a threat model entity on its respective threat model page, click the See more... link under the search results list.

Investigation search results. The complete list of results is displayed.