Sharing of Outbound Intelligence Records from GUI
This section outlines the functionality that enables users to share intelligence records directly from the Threat Intelligence (TI) Library within the TISC application.
Vorbereitungen
- sn_sec_tisc.analyst
- sn_sec_tisc.admin
Warum und wann dieser Vorgang ausgeführt wird
Access to the sharing templates is governed by multiple restrictions defined within each template. These restrictions specify whether a template is available to all the users or limited to specific users or user groups. Accordingly, only the templates allowed by these settings will be visible when users initiate the Share Intelligence process.
Only users with an analyst role can share the intelligence data from GUI to the external systems. Share intelligence feature also applies to the various other threat intelligence library entities including observables, indicators, and objects such as attack patterns, threat actors and so on.
Following is the procedure to share intelligence from the form view of observables records.
Prozedur
- Template Configuration: The entity tables displayed in this view are based on the sharing controls defined in the sharing template associated with the sharing record.
- Entity Grouping: The first high level grouping is Observables. Also, you will see child level observables such as File, IP Address, and other relevant types. Indicators and objects are also listed after Observables.
- Relationships: Displays relationships between the shared entities. Six different types of relationships are represented, each organized into its corresponding relationship table for clarity and structure.