> ## Documentation Index
> Fetch the complete documentation index at: https://docs.aviatrix.com/llms.txt
> Use this file to discover all available pages before exploring further.

# ThreatIQ

> ThreatIQ is deprecated in Aviatrix CoPilot 4.37. This UI reference is retained for customers with existing configurations.

<Warning>
  **ThreatIQ is deprecated in Aviatrix CoPilot 4.37.** The **Security >
  ThreatIQ** pages are removed from the CoPilot UI in 4.37 and later. Existing
  ThreatIQ configurations continue to operate on the backend. Migrate new threat
  detection to <a href={"/docs/enterprise/" + "10.1" + "/guides/security/threatiq-geo-dcf-migration-guidelines"}>Distributed Cloud Firewall with ExternalGroups</a>.
</Warning>

This section provides the purpose, elements, and actions performed on the
**ThreatIQ** pages.

<Tabs>
  <Tab title="Overview">
    ## Purpose

    The **Overview** page provides visibility into real-time threat detection and
    remediation across multicloud environments using Aviatrix ThreatIQ.

    ## Elements

    <Frame>
      <img
        src={
  "/images/reference/ui/security/threatiq-overview.png"
}
        alt="ThreatIQ: Overview"
        width="100%"
      />
    </Frame>

    * **Threat Summary Panel**: Displays detected threats, severity, and impacted
      resources. \* **Topology View**: Visualizes threat location and affected
      gateways. \* **Flow Data Panel**: Shows traffic flows triggering alerts. \*
      **ThreatGuard Status**: Indicates if automated remediation is active.

    ## Actions

    <AccordionGroup>
      <Accordion title="View ThreatIQ Overview">
        To view ThreatIQ threat detection and status:

        1. Go to **Security** > **ThreatIQ** > **Overview**.
        2. The Overview page appears with the **Threat Summary Panel** showing detected threats, severity, and impacted resources.
        3. Review **Topology View** to visualize threat location and affected gateways.
        4. Use **Flow Data Panel** to inspect traffic flows triggering alerts.
        5. Check **ThreatGuard Status** for automated remediation (drop rules) status.

        The Overview provides real-time visibility into threat detection and remediation
        across multicloud environments.

        ### Parameter Details

        | CoPilot Parameter Name | Description                                                    |
        | ---------------------- | -------------------------------------------------------------- |
        | Threat Summary         | Lists threats detected by ThreatIQ with severity levels.       |
        | Topology View          | Displays network topology highlighting impacted gateways.      |
        | Flow Data              | Shows source/destination IPs and ports for suspicious traffic. |
        | ThreatGuard Status     | Indicates if drop rules have been programmed automatically.    |
      </Accordion>
    </AccordionGroup>
  </Tab>

  <Tab title="Configuration">
    ## Purpose

    The **Configuration** page allows enabling ThreatIQ, customizing threat lists,
    and managing exclusion settings.

    ## Elements

    <Frame>
      <img
        src={
  "/images/reference/ui/security/threatiq-configuration.png"
}
        alt="ThreatIQ: Configuration"
        width="100%"
      />
    </Frame>

    * **Enable ThreatIQ Toggle**: Activates threat detection and alerting. \*
      **Custom Threat List**: Add or remove IPs/domains for monitoring. \* **Exclusion
      Settings**: Configure VPC/VNets to bypass ThreatIQ inspection.

    ## Actions

    <AccordionGroup>
      <Accordion title="Enable or Disable ThreatIQ">
        To enable or disable ThreatIQ threat detection and alerting:

        1. Go to **Security** > **ThreatIQ** > **Configuration**.
        2. Use the **Enable ThreatIQ** toggle to activate or deactivate threat detection and alerting.
        3. Save your changes if required.

        ThreatIQ is enabled or disabled according to the toggle state.

        ### Parameter Details

        | CoPilot Parameter Name | Description                                             |
        | ---------------------- | ------------------------------------------------------- |
        | Enable ThreatIQ        | Turns on ThreatIQ threat detection and alerting.        |
        | Custom Threat List     | Allows adding custom IPs/domains for threat monitoring. |
        | Exclusion Settings     | Configure VPC/VNets excluded from ThreatIQ inspection.  |
      </Accordion>

      <Accordion title="Manage Custom Threat List">
        To add or remove IPs or domains for monitoring:

        1. Go to **Security** > **ThreatIQ** > **Configuration**.
        2. In **Custom Threat List**, add or remove IPs or domains to monitor.
        3. Save your changes.

        Custom threat list entries are used for threat monitoring in addition to global
        feeds.
      </Accordion>

      <Accordion title="Configure Exclusion Settings">
        To configure VPC/VNets to bypass ThreatIQ inspection:

        1. Go to **Security** > **ThreatIQ** > **Configuration**.
        2. In **Exclusion Settings**, configure the VPC/VNets to exclude from ThreatIQ inspection.
        3. Save your changes.

        Excluded VPC/VNets are not inspected by ThreatIQ.
      </Accordion>
    </AccordionGroup>
  </Tab>

  <Tab title="Custom Threat List">
    ## Purpose

    The **Custom Threat List** page lets you add and manage a custom list of IP
    addresses that ThreatIQ treats as threat IPs.<br /><br />Custom threat IPs are
    handled by the Controller in the same way as threat IPs from the global threat
    source (detection, alerts, blocking, and unblocking). Use this list to monitor
    and block traffic to or from IPs you define as threats.

    ## Elements

    <Frame>
      <img
        src={
  "/images/reference/ui/security/threatiq-custom-threat-list.png"
}
        alt="ThreatIQ: Custom Threat List"
        width="100%"
      />
    </Frame>

    * **Custom Threat List table**: Lists the IP addresses, severity, color,
      classification, and notes you have added.
    * **+ Threat IP**: Adds a new threat IP entry to the list.
    * **Edit icon**: Edits an existing threat IP entry (double-click a value to
      change it, then save).
    * **Delete icon**: Removes an IP from the custom list; if blocking was applied
      for that IP, the Controller removes the rules from affected gateways.

    ## Actions

    <AccordionGroup>
      <Accordion title="Add a Custom ThreatIQ IP List">
        To add a custom list of threat IPs in ThreatIQ:

        1. Go to **Security** > **ThreatIQ** > **Custom Threat List**.
        2. Click **+ Threat IP**. An IP Deny List dialog appears.
        3. Enter the details. Refer to the Parameter Details table.
        4. To add more IPs, click the plus sign and enter the details for each.
        5. Click **Confirm**.

        The IP addresses are added to the database of known malicious hosts used by
        ThreatIQ.

        When those IPs are detected in traffic, they appear on the ThreatIQ map and are
        handled like other threat IPs (detection, blocking, unblocking). You must have
        `all_write` or `all_security_write` permissions to add a custom ThreatIQ IP
        list.

        ### Parameter Details

        | CoPilot Parameter Name | Description                                                                                     |
        | ---------------------- | ----------------------------------------------------------------------------------------------- |
        | IP                     | The IP address you consider a threat IP.                                                        |
        | Severity               | A term that indicates the severity of this threat IP (e.g. Major, Medium).                      |
        | Color                  | The color to associate with this threat IP; used in lists and charts on the ThreatIQ dashboard. |
        | Classification         | A term that indicates the classification of this threat IP.                                     |
        | Info                   | A custom note for this threat IP.                                                               |
      </Accordion>

      <Accordion title="Edit a Custom Threat IP Entry">
        To change an existing custom threat IP entry:

        1. Go to **Security** > **ThreatIQ** > **Custom Threat List**.
        2. Click the **Edit** icon for the entry you want to change.
        3. Double-click the value you want to change and enter the new value.
        4. Click the **Save** icon.

        Threat records created before the change keep their earlier values.
      </Accordion>

      <Accordion title="Delete an IP from the Custom Threat List">
        To remove an IP from the Custom Threat List:

        1. Go to **Security** > **ThreatIQ** > **Custom Threat List**.
        2. Locate the IP you want to remove and click the **Delete** icon.

        The IP is removed from the database of known malicious hosts used by
        ThreatIQ.<br /><br />If ThreatIQ blocking was applied for that IP, the Controller
        automatically removes the security rules for that threat IP from the affected
        gateways and traffic is no longer blocked for it.
      </Accordion>
    </AccordionGroup>
  </Tab>
</Tabs>
