Collaborating with Trusted Circles

Trusted circles are communities within ThreatStream in which you can participate, share threat intelligence in real-time, and get access to information others have shared. Trusted Circles are comprised of organizations with similar threat intelligence interests (due to their affiliation to an industry, supply chain, Incident, and so on) and enable these organizations to collaborate and discuss threat activities they have observed around a specific Campaign , adversary, or Incident. In addition to organizations that participate in Trusted Circles, the Anomali Threat Research team contributes and shares intelligence to the industry-specific Trusted Circles available on ThreatStream.

Sharing threat intelligence not only allows organizations to prepare their defenses in a timely manner but also join forces in thwarting a widespread attack.

For example, your organization is a member of a trusted circle made up of top 5 banks in the country. One of the members of this circle shares information about an Actor that tried infiltrating their servers last night. Chances are that this Actor will try other similar businesses. Your systems and servers may be the next target. Since you have received an early warning from your Trusted Circle community on ThreatStream, you can strengthen your defenses in time—set up firewall rules, block the Actor, and ensure your critical assets and data on them are under tight access controls.

When you participate in a Trusted Circle, you control what information is shared with other organizations in that circle. For example, if you want to share observables you are importing with your 2 of the 5 Trusted Circles you participate in, you have to explicitly set the Visibility for that import to those two Trusted Circles.