Navigate a Visualization

Updated 4 months ago by Sachit Soni

Introduction

The TruSTAR visualization provides analysts with a quick overview of the relationships between various reports and data sources they are subscribed to in the TruSTAR platform. The correlations are formed when reports share the same IOCs.  The rest of this page explains how to navigate the visualization and refine it.

Timeline Slider

The top part of the visualization consists of the timeline slider. The timeline allows the user to limit the date range of a given threat in view. To adjust the time range, click and hold one of the end caps and slide to the desired point. You can also select one of the predefined date ranges or create your own by selecting the Date Range selector. 

The timeline also shows the histogram (yellow bars) of correlations that have occurred on each day. Using this histogram you can quickly identify the days where a high number of correlations occurred. 

Graph Visualization

Below the timeline slider you can see the visualization of the correlations between reports and IOCs. 

Nodes

There are two types of nodes in the graph : IOC nodes and Report nodes. 

Report nodes are larger in size and IOC nodes are smaller in size.  Two report nodes can only be connected if they have 1 or more IOC nodes in common.

 

Node Navigation

Right clicking a node will now open shortcut options for:

  • Expand
  • Notes
  • Filter
  • Delete


Filter Sources

This allows the user to selectively hide IOCs, Sources and Tags that are not relevant to their analysis.

Undo/Redo/Refresh

Users can use these controls to undo, redo or refresh the visualization. If you refresh you will go back to the original graph.


How Did We Do?