ThreatQ Object Operation
Overview
ThreatQ Object operation for ThreatQ allows a ThreatQ user to interact with objects in complex ways to better manage the Threat Library.
The operation provides the following actions:
- Object Clone - creates a new object based on the original.
- Inherit from Children - bubble-up relationships and other context from child relationships.
The operation is compatible with the following system objects:
- Event
- Campaign
- Attack Pattern
- Malware
- Exploit Target
- Asset
- Tool
- Adversary
- TTP
- Report
- Intrusion Set
- Course Of Action
- Signature
- Vulnerability
- Identity
- Incident
- Indicator