Skip to main content
ThreatIQ is deprecated in Aviatrix CoPilot 4.37. The Security > ThreatIQ pages are removed from the CoPilot UI in 4.37 and later. Existing ThreatIQ configurations continue to operate on the backend. Migrate new threat detection to Distributed Cloud Firewall with ExternalGroups.
This section provides the purpose, elements, and actions performed on the ThreatIQ pages.

Purpose

The Overview page provides visibility into real-time threat detection and remediation across multicloud environments using Aviatrix ThreatIQ.

Elements

ThreatIQ: Overview
  • Threat Summary Panel: Displays detected threats, severity, and impacted resources. * Topology View: Visualizes threat location and affected gateways. * Flow Data Panel: Shows traffic flows triggering alerts. * ThreatGuard Status: Indicates if automated remediation is active.

Actions

To view ThreatIQ threat detection and status:
  1. Go to Security > ThreatIQ > Overview.
  2. The Overview page appears with the Threat Summary Panel showing detected threats, severity, and impacted resources.
  3. Review Topology View to visualize threat location and affected gateways.
  4. Use Flow Data Panel to inspect traffic flows triggering alerts.
  5. Check ThreatGuard Status for automated remediation (drop rules) status.
The Overview provides real-time visibility into threat detection and remediation across multicloud environments.

Parameter Details