Views:

View information about global threat actors and emerging threats on the threat report page.

The threat report page provides detailed information about threat actors or emerging threats selected from the Threat Intelligence Hub screen. The following table outlines the threat report page:
Section
Description
Summary
The top of the threat report page contains a summary of the threat. You can view additional information on the following tabs:
  • Overview: This tab displays a detailed history of the selected emerging threat or threat actor.
  • Risk Management Guidance: This tab provides suggestions of how your organization can manage the risks presented by the selected emerging threat or threat actor.
  • Threat Hunting Queries: This tab displays related threat hunting queries that you can run in XDR Data Explorer.
Intelligence Data
This section collects available threat intelligence from Trend Micro and third-party sources about the selected threat or threat actor. You can view more detailed information on the following tabs:
  • Intelligence Reports: This tab displays the intelligence reports associated with the selected threat or threat actor.
  • Tactics, Techniques, and Procedures: This tab lists the MITRE tactics and techniques associated with the selected threat or threat actor. Click the tactic or technique name to view more information on the MITRE website.
  • Tools: This tab lists software applications exploited by the selected threat or threat actor. Click the tool name to view more information.
  • Malware: This tab shows the malicious software used by the selected threat or threat actor. Click the malware name to view more information.
  • CVEs: This tab displays common vulnerabilities and exposures (CVE) associated with the selected threat or threat actor. Click the CVE ID to view more information.
  • Indicators: This tab lists indicators of compromise (IOCs) such as URLs and file hashes associated with the selected threat or threat actor. The selected threat or threat actor may also be associated with other IOCs.
  • Associated Threat Actors: This tab displays the associated threat actors of the selected emerging threat.
Impact Scope
This section highlights evidence of threats found in your environment.
Click the tabs to display any associated Workbench Alerts, as well as Servers, Endpoints, and Email Addresses containing matched IOCs.