Sightings

  • Release version: Xanadu
  • Updated August 1, 2024
  • 1 minute to read
  • Sightings denote that an indicator or object was seen. Objects may be a malware, tool, threat actor, and so on.

    Sightings track who and what is the target, how attacks are carried out, and to track trends in attack behavior.

    The Sighting relationship object contains extra properties not present in the generic relationship objects. These extra properties represent data specific to sighting relationships.

    For example, a count, or representing how many times something was seen.

    Sighting is captured as a relationship because you cannot have a sighting unless you have something that has been sighted.

    • What was sighted, such as the malware, campaign, or other SDO
    • Who sighted it and/or where it was sighted, represented as an identity
    • What was seen on systems and networks, represented as observed data