Features 3 min read

Tracked Entities & Keywords

Set up keyword tracking to personalize your feed and get alerts on topics that matter to you.

Tracked entities and keywords are the foundation of your personalized ThreatCluster experience. By telling the platform what you care about, you unlock a tailored "My Feed" that surfaces relevant clusters first and powers alert matching so you never miss a threat that matters to your organization.

What You Can Track

ThreatCluster supports tracking across a wide range of entity types:

Entity Type Examples
APT Groups APT29, Lazarus Group, Volt Typhoon
Ransomware Groups LockBit, BlackCat, Cl0p
CVEs CVE-2024-3094, CVE-2023-44228
Malware Cobalt Strike, QakBot, Emotet
Tools Mimikatz, Impacket, Brute Ratel
Campaigns Operation Triangulation, EastWind
MITRE ATT&CK Techniques T1059 (Command and Scripting Interpreter), T1566 (Phishing)
Companies Microsoft, Ivanti, Palo Alto Networks
Industries Healthcare, Financial Services, Energy
Countries United States, China, Russia
Platforms Windows, Linux, iOS, Kubernetes
Attack Types Supply chain, DDoS, credential stuffing

Adding Keywords

There are three ways to start tracking entities and keywords.

During Onboarding

When you first create your account, the onboarding flow asks you to select industries, threat actors, and other topics you want to follow. These become your initial set of tracked keywords.

From the Settings Page

Go to Settings > Keywords to add or remove tracked items at any time. Use the search field to find known entities by name, or type a custom keyword and press Enter.

From Entity Pages

When browsing a cluster or entity page, look for the Track button next to any entity name. Clicking it immediately adds that entity to your tracked list.

Tip: Tracking an entity from its page is the fastest way to build up your keyword list as you research threats organically.

Custom Keywords

Not every topic maps to a known entity. You can add free-text custom keywords to track anything -- product names internal to your organization, specific vulnerability descriptions, or niche threat terminology.

Custom keywords work the same way as entity-matched keywords for feed personalization and alert matching, but they won't link to an entity profile page.

Note: Custom keywords are matched as substrings, so a keyword like "ivanti" will match clusters mentioning "Ivanti Connect Secure" or "Ivanti EPMM." Keep keywords specific enough to avoid noisy matches.

How Personalization Works

When you switch to My Feed, ThreatCluster filters and ranks clusters based on your tracked keywords. The matching runs against:

  • Cluster titles -- both the original and AI-generated titles
  • AI summaries -- the short and extended summaries produced for each cluster
  • Extracted entities -- the structured entities (APT groups, CVEs, malware, etc.) identified within a cluster's articles

Clusters that match more of your tracked keywords rank higher. A cluster matching three of your keywords will appear above one matching only one.

Managing Your Keywords

All keyword management happens in Settings > Keywords. From there you can:

  • View your full list of tracked entities and custom keywords
  • Remove any keyword by clicking the delete icon next to it
  • Add new keywords using the search/input field at the top
  • See entity type labels next to each tracked item so you know what category it falls under

Regularly reviewing your keyword list keeps your feed focused. Remove keywords for campaigns that have concluded or threats you no longer need to monitor, and add new ones as your priorities shift.