Managing ThreatStream User Privileges

For each organization using the ThreatStream platform, there are three types of users: Org Admins, Non-admins, and Read Only users. Org Admins can perform administrative tasks that impact their entire organization on ThreatStream, whereas Non-admins can only manage settings that impact their personal profiles. Read Only users can view and export intelligence on ThreatStream but cannot create intelligence of any kind.

Org Admin Privileges

The tasks below are reserved for ThreatStream users with Org Admin privileges.

Task Description
Update organization name Update organization name in ThreatStream.
Update PDF export settings Change the number of search results and intelligences included in Search Result and Threat Bulletin PDF downloads respectively .
Configure organization-wide session timeout settings Enable ThreatStream session timeout for users in your organization and decide when timeouts occur after periods of inactivity.
Configure multi-factor authentication (MFA) Decide whether or not the organization requires multi-factor authentication for ThreatStream login.
Add/edit/delete organization users Add and remove users from the organization and update privileges for existing users.
Enable organization users to approve imports Configure privileges for non-admin users that enable them to evaluate imported observables.
Bypass MFA for organization users When MFA is enabled, Org Admins can configure users to avoid multi-factor authentication and login with their email address and password only.
Configure organization Exclude List Prevents users from within the organization from accidentally importing an organization CIDR, IP Address, Domain Name, URL, or Email Address.
Activate third-party integrations with ThreatStream Configure ThreatStream to use third-party services such as Farsight and Open DNS.
Manage premium intelligence streams Purchase and evaluate premium threat intelligence streams partnered with Anomali.
Create/leave/join Trusted Circles Enable the sharing of information between your organization and other organizations on ThreatStream.
Delete Threat Model entities Permanently delete Threat Bulletins, Actors, Campaigns, TTPs, Incidents, and Signatures that belong to your organization.
Audit user activity View user activity from the past 7 days.
Unlock Locked Accounts When user accounts in your organization are locked after consecutive failed login attempts, Org Admins can unlock accounts from the User Admin page within settings. See Managing Organization Users for more information.

The email lists below are reserved for ThreatStream users with Org Admin privileges.

Email List Description
Keyword Matches Sends notifications for each keyword match.
Keyword Matches Hourly Digest Sends summaries of all keyword matches from the last hour.

Non-admin Privileges

The tasks below can be performed by Non-admins and Org Admins.

Task Description
Edit personal contact information Edit personal email address, name, and phone number.
Change password used for ThreatStream login Change personal password used for ThreatStream login.
Update ThreatStream email subscriptions Users can configure which ThreatStream email lists their personal email address is included in.

The email lists below can be subscribed to by Non-admins and Org Admins.

Email List Description

Threat Bulletin Creation

Sends notifications every time a Threat Bulletin is created.
Threat Bulletin Daily Digest Sends summaries of Threat Bulletins created each day.
Trusted Circles Sends notifications when organizations join or leave your trusted circles.

Read Only User Privileges

Read Only users are restricted to viewing intelligence on ThreatStream and cannot create intelligence or related content such as tags, comments, or other metadata.

  • Read Only users do not count toward the number of users allocated to your organization in your ThreatStream license.

  • Read Only users can access ThreatStream OnPrem deployments that are on v4.1.1 and above. Read Only users cannot access ThreatStream OnPrem if it is on an earlier version.

  • Read Only users cannot use their ThreatStream accounts for single sign-on (SSO) on Security Analytics or ThreatStream Integrator.

The table below lists the features to which Read Only users have access.

Screen Available Features
Dashboard
  • View the Overview dashboard. Available widgets include Contributions, Indicators by Type, Intelligence Sources, My Recent Attacks, Organization Recent Sandbox Submissions, Threat Model Entities, Top ASNs, Top Impacts, and Top Threats by Country.
  • View the MyEvents dashboard.
  • View the Community Threats dashboard
  • Add shared custom dashboards created by fellow organization users and themed dashboards created by the Anomali Threat Research team to their homepages on ThreatStream.
Analyze > Overview View and drill down on recent threat model entities.
Analyze > Observables
  • Perform basic observable searches.
  • Perform advanced observable searches.
  • View observable details pages.
  • Export observables from the observables search page and details pages.
Analyze > Threat Model
  • Perform basic Threat Model entity searches.
  • Perform advanced Threat Model entity searches
  • View Threat Model entity details pages.
  • Export Threat Model entities from threat model entity details pages.
Research > Sandbox
  • View sandbox report details.
  • Export sandbox reports.
Research > Collaborate

Chat with organization and trusted circles members.

Note: This menu item is only visible if the Can Use Chat permission is enabled for a user on the User Admin tab. See Managing Organization Users for more information.
APP Store > APP Store Browse available APP Store services.
Settings > My Profile
  • Update user Email, Name, and Phone.
  • Change account password.
  • Subscribe to the Threat Model Daily Digest email.
  • View API Key if the Show API Key for Users permission is enabled for a Read Only user on the User Admin tab. Refer to Managing Organization Users for details.