Managing ThreatStream User Privileges
For each organization using the ThreatStream platform, there are three types of users: Org Admins, Non-admins, and Read Only users. Org Admins can perform administrative tasks that impact their entire organization on ThreatStream, whereas Non-admins can only manage settings that impact their personal profiles. Read Only users can view and export intelligence on ThreatStream but cannot create intelligence of any kind.
Org Admin Privileges
The tasks below are reserved for ThreatStream users with Org Admin privileges.
| Task | Description |
|---|---|
| Update organization name | Update organization name in ThreatStream. |
| Update PDF export settings | Change the number of search results and intelligences included in Search Result and Threat Bulletin PDF downloads respectively . |
| Configure organization-wide session timeout settings | Enable ThreatStream session timeout for users in your organization and decide when timeouts occur after periods of inactivity. |
| Configure multi-factor authentication (MFA) | Decide whether or not the organization requires multi-factor authentication for ThreatStream login. |
| Add/edit/delete organization users | Add and remove users from the organization and update privileges for existing users. |
| Enable organization users to approve imports | Configure privileges for non-admin users that enable them to evaluate imported observables. |
| Bypass MFA for organization users | When MFA is enabled, Org Admins can configure users to avoid multi-factor authentication and login with their email address and password only. |
| Configure organization Exclude List | Prevents users from within the organization from accidentally importing an organization CIDR, IP Address, Domain Name, URL, or Email Address. |
| Activate third-party integrations with ThreatStream | Configure ThreatStream to use third-party services such as Farsight and Open DNS. |
| Manage premium intelligence streams | Purchase and evaluate premium threat intelligence streams partnered with Anomali. |
| Create/leave/join Trusted Circles | Enable the sharing of information between your organization and other organizations on ThreatStream. |
| Delete Threat Model entities | Permanently delete Threat Bulletins, Actors, Campaigns, TTPs, Incidents, and Signatures that belong to your organization. |
| Audit user activity | View user activity from the past 7 days. |
| Unlock Locked Accounts | When user accounts in your organization are locked after consecutive failed login attempts, Org Admins can unlock accounts from the User Admin page within settings. See Managing Organization Users for more information. |
The email lists below are reserved for ThreatStream users with Org Admin privileges.
| Email List | Description |
|---|---|
| Keyword Matches | Sends notifications for each keyword match. |
| Keyword Matches Hourly Digest | Sends summaries of all keyword matches from the last hour. |
Non-admin Privileges
The tasks below can be performed by Non-admins and Org Admins.
| Task | Description |
|---|---|
| Edit personal contact information | Edit personal email address, name, and phone number. |
| Change password used for ThreatStream login | Change personal password used for ThreatStream login. |
| Update ThreatStream email subscriptions | Users can configure which ThreatStream email lists their personal email address is included in. |
The email lists below can be subscribed to by Non-admins and Org Admins.
| Email List | Description |
|---|---|
|
Threat Bulletin Creation |
Sends notifications every time a Threat Bulletin is created. |
| Threat Bulletin Daily Digest | Sends summaries of Threat Bulletins created each day. |
| Trusted Circles | Sends notifications when organizations join or leave your trusted circles. |
Read Only User Privileges
Read Only users are restricted to viewing intelligence on ThreatStream and cannot create intelligence or related content such as tags, comments, or other metadata.
-
Read Only users do not count toward the number of users allocated to your organization in your ThreatStream license.
-
Read Only users can access ThreatStream OnPrem deployments that are on v4.1.1 and above. Read Only users cannot access ThreatStream OnPrem if it is on an earlier version.
-
Read Only users cannot use their ThreatStream accounts for single sign-on (SSO) on Security Analytics or ThreatStream Integrator.
The table below lists the features to which Read Only users have access.
| Screen | Available Features |
|---|---|
| Dashboard |
|
| Analyze > Overview | View and drill down on recent threat model entities. |
| Analyze > Observables |
|
| Analyze > Threat Model |
|
| Research > Sandbox |
|
| Research > Collaborate |
Chat with organization and trusted circles members. Note: This menu item is only visible if the Can Use Chat permission is enabled for a user on the User Admin tab. See Managing Organization Users for more information.
|
| APP Store > APP Store | Browse available APP Store services. |
| Settings > My Profile |
|