Viewing Report Details
On the Security Reporting page, you can click any report to view its details. Each report includes common report attributes such as the report name, visibility, status, creation date, and last modified date, along with report content defined by the threat type and the report template or PIR used to generate it.
To learn how reports are generated from PIRs, see Configuring PIR Outputs.
Below is a report example generated by a PIR.
(Click the image to enlarge it)
Report name.
Report Status.
Possible values include:
-
Draft—report is still being created or edited, and its content may be incomplete or unverified.
-
In Review—report has been completed by the author and is undergoing validation.
-
Published—report is finalized and approved.
Report Author: User who created the report
Visibility: Report visibility indicating who can access this report.
Possible values include:
-
Private—report is visible only to the author.
-
My Organization—report is visible to all organization users.
-
Anomali Community—report is visible to all ThreatStream Next Gen users, inside and outside of your organization.
TLP: Traffic Light Protocol (TLP) associated with the report. The TLP color provides a mechanism to communicate to report readers whether further dissemination of information in the report is allowed; if yes, how freely can this information be distributed.
To learn more about TLP, search for "Traffic Light Protocol" in your favorite search engine.
Report Date: Timestamp of when the report was created.
Last Modified: Timestamp of when the report was last modified.
Tags: Tags associated with this security report.
Report Text: The content of reports can vary depending on how they are created. Manually created reports typically include the sections defined by the template used at the time of creation (unless those headers have been modified or removed).
Reports generated by a PIR usually follow a more structured format. They always include an executive summary that highlights key findings such as identified threats, affected assets and the overall significance of the activity. They also contain technical details, including identified vulnerabilities, associated infrastructure, ISP information, and scan results. In addition, PIR-generated reports include a risk assessment and recommendations, as well as PIR-specific metadata such as the PIR name, category, description, priority, tags, and the data sources used during execution.
Edit: Edit the report. See Editing a Report From the Report Details Page for details.
Horizontal more options menu (...):
-
Publish/Unpublish: Publish or unpublish the report. See Publishing a Report From the Report Details Page for details.
-
Threat Bulletin (coming soon)
-
Export As PDF: Export the report to PDF. See Exporting Reports to PDF for details.
-
Schedule (coming soon)
-
Share (coming soon)
