Intel Submissions is the process of adding or sharing new threat intelligence data such as, IoCs, tactics, techniques, procedures, threat actors, malware signatures, or vulnerability details for analysis, correlation, and distribution. This helps to detect, investigate, and respond to threats more effectively.
The Submissions by Users tab helps you to view and analyze all the incoming intel. You can view the submitted intel details, their severity (critical, high, medium, low) and filter the intel by specific date range that is last 1 day, last 7 days, last 1 month, last 3 months, and last 1 year.
Adding New Intel
To add a new intel, follow these steps:
- On the Seqrite Threat Intelligence portal, click Submissions by Users in the left pane.
- On the Submissions by Users page, click + Add Intel.
- Select the Category from the list, enter Basic and Additional Details.
- If you want to review the intel before submission, click Save Draft else click Submit.
The Add New Intel page is displayed.
This provision is also available to Org/Regulated Entity Admins as well.
Viewing the Submitted Intel
You can view the intel submissions details such as severity (Critical, High, Medium, Low) highlighted with the color codes, Sub ID (Submission ID), Intel ID, title, reported on, approved on, and the status in the tabular format.
To view the details of each intel, follow these steps:
- On the Seqrite Threat Intelligence portal, click Submissions by Users in the left pane.
- On the Submissions by Users page, select the intel and click the > icon.
- The intel submission details page displays the following details:
- Primary Information: For example, APT Category (Category, Name, Source IP, Description, APT Name, IoC Type, IoC Name)
- Additional Information : Incident Date, Severity, Tags, Risk ratings, and Confidence Core.
- Reason for Approve/Reject: Shows reason for intel approval or rejection.
Filtering the Submitted Intel
You can filter the intel submissions list to refine results based on submission ID, intel ID, submission title, reported on, approved on, and submission status.
To filter the intel submissions list, follow these steps:
- On the Seqrite Threat Intelligence portal, click Submissions by Users in the left pane.
- On the Submissions by Userss page click
.
- Enter the details that are, submission ID, intel ID, submission title, reported on, approved on, and submission status and then click Apply.
The system displays filtered data.
Exporting Intel Submissions as a CSV
You can download all the intel submissions currently visible on the page in the CSV format.
To export/download intel submissions, follow these steps:
- On the Seqrite Threat Intelligence porta, click Submissions by Users in the left pane.
- On the Submissions by Users page click Export CSV.