First Steps for Administrators

The following tasks are recommended for Org Admins setting up their organizations on ThreatStream.

Add additional analysts and administrators

Do you need to add additional administrators? Will anyone else on your team of analysts (Non-admin) use ThreatStream?

To learn more about adding additional users to your organization on ThreatStream, see Managing Organization Users .

There are three user types: Org Admins, Non-admins, and Read Only users. To read more about privileges for each user type, read Managing ThreatStream User Privileges

Configure multi-factor authentication

ThreatStream enables the use of multi-factor authentication (MFA) with Google authenticator to provide your organization and data with an extra layer of security. While not required, Anomali highly recommends the use of multi-factor authentication on ThreatStream.

To read more about multi-factor authentication and how to set it up, read Multi-Factor Authentication.

Set up organization exclude list

Setting up an exclude list for your organization can save you valuable time in the future by preventing users within your organization from importing known safe CIDRs, IP Addresses, Domain Names, URLs, or Email Addresses from your organization.

To learn more about setting up a exclude list and view recommended entries to include, read Updating Organization Exclude List

Configure Rules

Rules are valuable tools in combating attacks and enable your organization to take immediate action when specific keywords appear in observables, Sandbox reports, or Threat Bulletins.

To learn more about configuring rules, see Rules.

Join Trusted Circles

Trusted circles are communities within ThreatStream in which you can participate, share threat intelligence in real-time, and get access to information others have shared. To read learn more about joining Trusted Circles on ThreatStream, read Collaborating with Trusted Circles .