View Threat Intelligence Security Center Homepage
Use the TISC homepage which is the landing page, to visualize the threat intelligence related data.
Before you begin
Role required: sn_sec_tisc.analyst
Procedure
-
Navigate to All > Workspaces > Threat Intelligence Security Center.
The TISC Home Page is displayed.
-
View the TISC homepage with different widgets data.
The homepage view consists of two different tabs: Feeds Overview and Trending Threats. The content on the homepage comes from various sources such as observables, indicators, and data feeds.
- Feeds Overview: This tab provides a high level overview of different sources that the data is ingested and sources that are configured for the data ingestion.
Table 1. Feeds Overview Widget Name Description Action Number of Sources Displays the number of sources by status such as draft, enabled, and disabled in the system. When this widget is clicked, the list page is opened with the filtered records. Active Sources by Source Type Displays the distribution of active sources by source type. When this widget is clicked, the list page is opened with the filtered records. Active Sources by Feed Format Displays the number of enabled sources by Feed Type. When this widget is clicked, the list page is opened with the filtered records. Total Active Observables (30 days) Displays the top 10 sources by volume of intelligence records that were created in the last 30 days. When this widget is clicked, the KPI details page of the widget for the selected filter is opened in a new tab. Active Observables by Type Displays the top total volume of observable aggregates that were created in the last 30 days. When this widget is clicked, the KPI details page of the widget for the selected filter is opened in a new tab. Active Indicators by Pattern Type Displays the total volume of Indicator aggregates by pattern type that were created in the last 30 days. When this widget is clicked, the KPI details page of the widget for the selected filter is opened in a new tab. Total Active Indicators (30 days) Displays the total volume of indicator aggregates that were created in the last 30 days. When this widget is clicked, the KPI details page of the widget for the selected filter is opened in a new tab. Top Sources by False Positives Count (30 days) Displays the total volume by of False Positive observables that were created in the last 30 days. When this widget is clicked, the list page is opened with the filtered records. - Trending Threats: This tab provides a high level overview of the trending threats.
Table 2. Feeds Overview Widget Name Description Action Latest Reports (Top 10) Displays the list of reports and links - Top 10 order by published date. When this widget is clicked, the list page is opened with the filtered records. Latest RSS Feeds (Top 10) Displays the list of RSS feeds and links - Top 10 order by published date. When this widget is clicked, the list page is opened with the filtered records. Active Observables by Threat Score Range (30 days) Displays the observables count that were created in the last 30 days distributed by Threat Score ranges. When this widget is clicked, the KPI details page of the widget for the selected filter is opened in a new tab. Active Observables by Reputation (30 days) Displays the observables count that were created in the last 30 days distributed by Reputation. When this widget is clicked, the KPI details page of the widget for the selected filter is opened in a new tab. Top tags (30 Days) Displays the top tags on the records created in the last 30 days based on the frequency of usage. When this widget is clicked, the KPI details page of the widget for the selected filter is opened in a new tab. Most Targeted Sectors (30 days) Displays the top 10 sectors ranked by activities reported that were created in the last 30 days. When this widget is clicked, the KPI details page of the widget for the selected filter is opened in a new tab. - Feeds Overview: This tab provides a high level overview of different sources that the data is ingested and sources that are configured for the data ingestion.