Adding Threat Model Entities to Investigations
To start an investigation of a threat model entity, you must add it to an investigation. Threat model entities can be added to investigations from the Threat Model list page or from investigations.
To learn how to add threat model entities from investigations, see Managing Investigation Entities.
To add a threat model entity to an investigation from the Threat Model list page:
-
Navigate to ThreatStream > Analyze > Threat Model.
-
Select the threat model entity that you want to add to an investigation.
-
Click Add to Investigation.
-
In the dialog box that opens, select the investigation to which you want to add the threat model entity.
-
In the dialog box that opens, click Yes.
Alternatively, you can create a new investigation and add a threat model entity to it.
To create a new investigation from the Threat Model list page:
-
Navigate to ThreatStream > Analyze > Threat Model.
-
Locate and select one or more threat model entities that you want to add to an investigation.
-
Click Add to Investigation.
-
In the dialog box that opens, click Create new investigation.
-
Fill out the New Investigation form.
Click Create.Property Description Name Enter a meaningful name. Visibility Select a Visibility setting for the investigation. By default, the investigation is visible only to you. You can expand visibility to all users in your organization (My Organization), workgroups, or a set of individual users in your organization. Assignee Select a user or a workgroup that will be conducting the investigation.
Here, you can also create a new workgroup.To create a new workgroup:
1. Click the arrow under the Assignee value.
2. Click +New workgroup.
3. Enter a meaningful name and select an image to use it as a workgroup avatar.
4 Click New workgroup. The new workgroup is created and is available under the Assignee property.
Description Provide the description for the investigation. Model Select the investigation model. Selected Items Select Add Observables from selected Entities if you want to add observables from the selected threat model entities.
The newly created investigation is added to the list of investigations.