Viewing Threat Model Entity History
Each threat model entity details page contains a running list of events in the life span of the entity. Events include entity creation and updates, such as editing descriptions, publishing an entity, uploading attachments, and so on.
User: User who updated the entity. For entities owned by your organization, specific users are listed. For entities from other organizations shared through Trusted Circles, the following rules are followed:
-
If the entity is owned by the organization, only the organization name is listed.
-
If the organization does not own the entity, the organization name is also hidden.
-
For entities shared with the Anomali Community or anonymously through Trusted Circles, no value is shown regardless of ownership.
Action: Action taken on the entity.
For Threat Bulletins, actions include: Assigned Report, Association Added, Association Removed, Cloned Report, Created Attachment, Created Comment, Created Report, Deleted Attachment, Deleted Comment, Published Report, Reviewed Report, Review Requested, Updated Import Session, Updated Intelligence, Updated Report, and Updated Tag.
For all other Threat Model entities, actions include: Assigned, Association Added, Association Removed, Completed Review, Created, Created Comment, Published, Review Requested, Updated, and Updated Tag.
Timestamp: Timestamp from when the action was taken.
To view a threat model entity history:
- Navigate to ThreatStream > Analyze > Threat Model.
- Click the entity whose history you want to view. The entity details page is displayed.
- On the entity details page, open the History tab.