Using the Anomali Threat Model

The Anomali Threat Model is STIX (v1.2, v2.0, and v2.1) compatible and supports adding, managing, importing, and exporting contextual, relationship, and workflow information for these types of Threat Model entities: Actors, Attack Patterns, Campaigns, Courses of Action, Custom Objects, Identities, Incidents, Infrastructure, Intrusion Sets, Malware, Signatures, Tools, Threat Bulletins, Tools, TTPs, and Vulnerabilities.

Note: For a complete list of STIX v1.2, v2.0, and v2.1 attributes supported for each entity type in ThreatStream, see Supported Attributes for STIX Entities. Only the attributes listed in this appendix are supported.

Although the Threat Model is pre-populated with a large set of information, you can add additional Actors, Campaigns, Incidents, TTPs, and Signatures through the ThreatStream UI or import this information. Observables can be imported using Import Assistant. See Importing Observables with Import Assistant for more information. You can also export the Threat Model information from ThreatStream.

Maintaining relationships across Threat Model entities provides additional context around threats and allows you to use ThreatStream for a deeper analysis of observables rather than viewing atomic observables. The rich contextual data and relationship information can also be useful in making better policy decisions for SIEM and other security automation use cases for your infrastructure.

The Anomali Threat Model provides bidirectional associations between entities of all threat model types, including entities of the same threat model type. Therefore, the UI always displays a bidirectional relationship between two entities. For example, if an Actor is shown to be related to a Campaign then that Campaign is also shown as related to the Actor. Bidirectional associations can also be created between Threat Model entities and Observables, Threat Bulletins, and Vulnerabilities. Threat Model entities of all types can also be associated with Sandbox Reports, though these associations are unidirectional and not displayed on the Sandbox Report details page. Additionally, you can add labels to Threat Model and observables associations to track contextual information. See Adding Labels to Associations for more information.

Threat Bulletins

The Threat Model also supports the Threat Bulletin feature. Threat Bulletins—news flashes, articles on Malware or attacker infrastructure, data dumps, and so on—provide simple write-ups on events. Although the information in a Threat Bulletin depends on the template used when the Threat Bulletin was created, a typical Threat Bulletin consists of a summary of the event, source of the Threat Bulletin, any tags associated with the event (an alias by which the event may also be known), details of the event, and any observables associated with the event.

See Viewing Threat Bulletin Details for more information.

Vulnerabilities

ThreatStream imports a large number of Vulnerabilities from outside sources, such as the National Vulnerability Database, on a daily basis. These system imported Vulnerabilities can be distinguished from non-system imported Vulnerabilities as they display a MITRE EXTERNAL LINK in the Attributes section of the details page.

You can create associations between Vulnerabilities and all threat model entities, Observables, Threat Bulletins, Sandbox Reports, and other Vulnerabilities. System imported Vulnerabilities can be associated with observables during import by adding Vulnerability titles as tags to the import session. See Importing Observablesfor more information.

Public vs Private

The Threat Model information you add to ThreatStream follows the same privacy paradigm that all other methods of intelligence (import, sandbox, Threat Bulletin) follow. You can select whether the data you are adding is available to everyone (Anomali Community), accessible to your organization only (My Organization), or shared with Trusted Circles.

Threat Model Operations

Threat Model Dashboard

Accessing Threat Models

Adding New Threat Model Entities

Reviewing Threat Model Entities for Publication

Bulk Tag Management of Threat Models

Adding Private Tags to Threat Model Entities

Adding Threat Model Entities to Investigations

Sharing Threat Model Entities via Email

Deleting Threat Model Entities

Cloning Threat Model Entities

Creating Description Templates From Threat Models

Restricting Threat Model Entities to Workgroups

Exporting Threat Model Entities in PDF Format

Exporting Threat Model Entities in STIX Format

Performing Advanced Threat Model Searches

Saving Threat Model Search Filters

Adding Labels to Associations

Using MITRE ATT&CK Frameworks in Threat Models

Managing STIX Relationship Objects (SROs)

Viewing Threat Model Entity History