Associating an Observable with Other Observables
In addition to bidirectional associations between observables and threat model entities, ThreatStream enables you to associate observables with other related observables. Associations appear in the Associations table on observable details pages, allowing you to quickly and easily pivot between related observables.
To associate an observable with another observable:
- Navigate to the details page of the observable for which you want to add the association.
- Under Associations, click Observables.
- Click Add.
- Enter a search query and select the observables you want to add as associations.
- Click Add Observables.
To remove observable associations:
- Navigate to the details page of the observable for which you want to remove the association.
- Under Associations, click Observables.
- Select the observable you want to disassociate.
- Click Remove.