Threat Intelligence Security Center Parent Identification LogicSummary<!-- /*NS Branding Styles*/ --> .ns-kb-css-body-editor-container { p { font-size: 12pt; font-family: Lato; color: var(--now-color--text-primary, #000000); } span { font-size: 12pt; font-family: Lato; color: var(--now-color--text-primary, #000000); } h2 { font-size: 24pt; font-family: Lato; color: var(--now-color--text-primary, black); } h3 { font-size: 18pt; font-family: Lato; color: var(--now-color--text-primary, black); } h4 { font-size: 14pt; font-family: Lato; color: var(--now-color--text-primary, black); } a { font-size: 12pt; font-family: Lato; color: var(--now-color--link-primary, #00718F); } a:hover { font-size: 12pt; color: var(--now-color--link-primary, #024F69); } a:target { font-size: 12pt; color: var(--now-color--link-primary, #032D42); } a:visited { font-size: 12pt; color: var(--now-color--link-primary, #00718f); } ul { font-size: 12pt; font-family: Lato; } li { font-size: 12pt; font-family: Lato; } img { display: ; max-width: ; width: ; height: ; } } Parent Identification: Key or Parent Identification fields are those using whose values a parent/aggregated record is identified in the system . These key fields can be single Or a combination of fields for different entities in the system Eg : If name for sourceRecord1 is A , name for sourceRecord2 is B , name for sourceRecord3 is A . SourceRecord1 , sourceRecord3 are mapped to AggregateRecord1, While sourceRecord2 as name is different is mapped to a different aggregation record aggregateRecord2 Observable Source Parent Identification Entity Key Fields Observable Source (For all observable Types except "Other" type of observable) Value, Type "Other" type of observable source Value, Type, Type From Source Indicator Source Parent Identifcation Entity Key Fields Indicator Source Name, Pattern Type Object Source Parent Identifcation Entity Key Fields Vulnerability Source Name, Spec Version, Revoked Threat Event Source Name, Spec Version, Revoked Location Source Name, Spec Version, Revoked Threat Opinion Source Opinion, Spec Version, Revoked Attack Pattern Source Name, Aliases, Spec Version, Revoked Identity Source Name, Identity Class, Spec Version, Revoked Course Of Action Source Name, Spec Version, Revoked Intrusion Set Source Name, Spec Version, Revoked Malware Analysis Source Product, Operating System, Host VM, Spec Version, Revoked Malware Source Name, Is Family, Spec Version, Revoked Threat Actor Source Name, Aliases, Spec Version, Revoked Threat Note Source Content, Spec Version, Revoked Tool Source Name, Spec Version, Revoked Campaign Source Name, Aliases, Spec Version, Revoked Infrastructure Source Name, Spec Version, Revoked Object Sighting Source Is Summary, Is Local, Sighting Of ( Relationship Record), Spec Version, Revoked Observed Data Source Observed Count, First Observed, Last Observed, Spec Version, Revoked Threat Grouping Source Context, Spec Version, Revoked Threat Report Source Name, Published, Spec Version, Revoked Marking Definition Source Name, Definition Type, Definition, Spec Version, Revoked Data Source – Source Name, Spec Version, Revoked Data Component Source Name, Data Source, Spec Version, Revoked Related KB Please refer to the following knowledge base articles for detailed information regarding other elements of TISC processing workflow: KB1587756: This KB article provides details regarding the De-duplication logic for entities in TISC, which happens after Parent Identification phase in the processing layer. KB1587758: This KB article provides details regarding the aggregation logic implemented in the TISC Processing layer, which is executed immediately following the De-duplication phase.