Threat Intel
Threat Intel
This screen summarizes threat activity for a selected period and shows threat history as cards per asset (IP), employee, and department.
Selecting the Period
Set the query period at the top right. The default is the last 1 day.
- Pick the start/end time directly in the date range picker.
- Choose a step unit (1 hour / 1 day / 1 week / 1 month) and use the ◀ / ▶ buttons to move the window by that unit. Moving past the present clamps to the current time.
- Changing the period reloads the overview, trend, and top panels.
Screen Layout
- Threat overview — total threat level and the number of assets with threats in the selected period.
- Threat trend — a time-series chart of threat scores. Hover to see per-time values; the bucket interval adjusts automatically to the period length.
- Top 3 panels — top assets / employees / departments by threat, each with a horizontal bar. The delta next to each value compares against the previous window of the same length (red for increase, green for decrease). Assets show the hostname first when known.
or navigate directly with the URL format below.
Intel Card
Clicking an item in a top panel slides in the intel card on the right. Close it by clicking the backdrop, the ✕ button, or pressing Esc.
- Header: total threat score with a grade badge, the entity name (IP or person), and secondary info (hostname / employee key and department).
- Four grades: score ≥ 1000 Critical (red), ≥ 100 Suspicious (orange), ≥ 10 Notable (blue), otherwise Low (green).
Detection Status Tab
The first tab on every card.
- Summary — first/last seen, total events, total threat level, technique and tactic counts. IP cards also show GeoIP-based ASN and country.
- Detection rules — per-rule counts with priority badges (HIGH/MEDIUM/LOW).
- MITRE TTP — chips for observed tactics and techniques (such as T1595).
- Recent events — time, source → destination, rule, and priority. Source and destination IPs are links: click one to pivot straight to that IP's card.
Sharing by URL
Copy the URL while a card is open to share or bookmark it. The entity is carried in the URL fragment.
…/threat-intel#ipv4-addr/172.20.128.63— an IP card…/threat-intel#employee/20240001— an employee card (employee key)…/threat-intel#department/D100— a department card (department code)
The browser back button closes the card and returns to the list.
App Extension Tabs
On IP cards, tabs provided by installed apps appear automatically after the Detection Status tab. Each tab shows the providing app's icon and loads when clicked.
For example, installing the Genian NAC app adds these tabs to IP cards:
| Tab | Contents |
|---|---|
| NAC Node | Node information registered in NAC (status, MAC, platform, user, department, …) |
| CVE | CVE vulnerabilities NAC knows for the IP |
| Open Ports | Detected open ports and services |
Extension tabs disappear when the providing app is stopped or removed. To provide extension tabs from your own app, see App Extension.