Documentation
How ThreatDoc works
Documents are built in the ThreatDoc desktop app. The website is only for your account, billing, and team.
Getting Started
Installing the desktop app, getting your account key, and creating your first document.
Creating an account
- Create an account on the website using the sign up page
- You'll receive a confirmation email to the provided address
- After confirming your email, an MFA onboarding prompt appears. Set up MFA with an authenticator application, or skip it for now
- Set your team name and members, or manage billing and two factor auth on the website
Installing the desktop app
- Download and install ThreatDoc Desktop, an account key will be generate the first time the application opens
- This account key is never saved and required on every initialization
- The app works fully offline for local only documents, go online and sign into your ThreatDoc account only when you want to sync a document to the cloud
- Clients you add on desktop are local to that device by design, separate from your account and never synced
Creating a Document
- From Documents tab, click "+ Create Document"
- Optionally link a local client, and set engagement start and end dates
- See Documents for features like sections and artifacts
Opening a file directly
- Right click a .tdoc file, or a .docx you want to import, and choose "Open with ThreatDoc Desktop"
- Opens a light weight window for editing this imports the document without needing to launch the main app or go through an import dialog first
- Insert account key, note this does not encrypt the file on the drive but the stored data inside the application just like exporting. Use ThreatDoc Folder to store raw files for encryption
Document workflow
- A new document is local only until you choose to sync it
- Add artifacts from the Artifacts tab or the Engagement Workspace checklist
- Write the document's sections directly in the editor, everything autosaves locally as you type
- Review PDF export and select built in options or select Custom and design your own
- Export PDFs, DOCX, or TDOC (built in file type of transfer between devices)
- Click Upload to Cloud to back up or share a document, this is what counts against your storage, not local work
Deleting a Document
- "Delete locally" removes it from this device only. The cloud copy, if any, is untouched
- "Delete locally and on ThreatDoc" removes it everywhere, including its artifacts, evidence, and generated PDF, this can't be undone
- "Remove from cloud" frees up your storage quota while keeping your local copy, sync again later to reupload it
Documents
Artifacts
An artifact starts as just a title. Open it to optionally apply the Finding or Control Item preset for a ready made field set and badge, or skip both and build your own, adding, renaming, reordering, and removing fields freely, at any time, preset or not.
Adding artifacts
- From the Artifacts tab, or by running a checklist in the Engagement Workspace, which always applies the Finding or Control Item preset directly
- Give it a title, then decide how to define it, a preset is entirely optional
Finding preset
- Adds severity, plus description, impact, affected assets, proof of concept, and recommendation fields
- Search the built in finding template catalog, covering CWE, OWASP Top 10, and more, to prefill a title, a suggested severity, and starting content
Control item preset
- Adds a control ID, target completion date, and implementation status, plus responsible party, weakness description, and milestones fields
- Search the NIST SP 800-53 control catalog to prefill the control ID and title
Building your own
- Add a field with a name and a kind, rich text, plain text, or date, then drag to reorder it
- Rename or delete a field at any time, this works the same whether it came from a preset or not
- Set a custom badge value, shown the same way a finding's severity is
Evidence
- Attach one or more images to an artifact, with an optional description
- Insert an evidence image directly into any editor for that document
- Evidence you sync to the cloud is encrypted the same way as everything else, see Encryption & Cloud Sync
Templates, Checklist & Scanner Import
Templates
- When defining an artifact from a preset, search the built in finding or NIST 800-53 control catalog to prefill it, see Artifacts above
- Use document section templates to spend less time rewriting a document's overall structure
Checklist
- Open Workspace and select a document and a checklist referencing frameworks like NIST SP 800-115
- Mark each item as a deviation or as meeting expectations
- A note you add becomes that item's finding description
- Toggle whether meeting expectations also logs an informational finding
Scanner Import
- Open Workspace, select a document, and switch to the Scanner Import tab
- Upload a Nessus (.nessus), Burp Suite XML, Nmap XML, or CSV export
- Repeated hits for the same issue are grouped into one row listing every affected host, not one row per host
- Review the detected items and pick which ones to keep before anything is created.
- On a testing style document, selected items become findings with severity carried over; on an assessing style document, they become control items marked Not Implemented
- Everything is parsed and matched locally, the scanner file never leaves your device
PDF Options, Preview & Retesting
- Choose a PDF layout, or select custom that opens a canvas to add linked text, logos, and shapes
- For built in layouts, select a theme or custom colors and toggle selections
- Reorder artifacts within a section and hide any of them, or hide individual fields within one, without touching the underlying data
- A live preview on the right updates a moment after every change, so you're never generating blind
- Choose the Custom cover layout to drag, drop, and resize text, your logo, and shapes freely on the cover page, each text element can show your own words or stay bound to a document field, a section, or a specific artifact's field
- A custom layouts do not automatically save so make sure to save before leaving the tab
- "Generate POA&M" produces a tabular PDF listing every artifact on the document, not just control items
Inline Functions
- In any document editor, type "@" to start an inline function
- Available functions autosuggest as you type, and can be navigated with the up/down arrows
- Use a findings by severity function for a pie or bar chart, a snapshot ordered by severity at that moment
- Reference any artifact by title to insert a label styled with its title and badge value, or reference one of its specific fields to pull that content directly into the PDF
Encryption & Cloud Sync
Local documents are always encrypted at rest on your device using a key tied to that device, whether or not you ever sync anything.
Zero knowledge cloud sync
- The first time you open the application, the desktop app generates your account key and shows it to you once. Save it somewhere safe, it's never shown again and ThreatDoc can't recover it
- Every document you create is encrypted on your device with a key derived from your account key. If synced, the server only ever stores ciphertext, plus enough information to check a key is correct, never the key or your plaintext content
- Team documents work the same way but use one shared team key instead, so any active member can open them, see Teams below
Key rotation
- Rotate your account key (or, if you lead a team, the team key) from Settings in the desktop app at any time
- Rotation reencrypts every affected document under a new key.
- Rotation protects documents going forward, including cutting off a departed team member's access to anything synced afterward. It can't retroactively revoke a copy someone already downloaded
Teams
Creating a team
- Teams are a Pro feature, the leader needs a Pro account
- Create a team and invite members from the Team page on the website
Inviting a member
- Adding a member either requires them to already have a Pro account, or adds a $20/mo seat charge to the leader's subscription
- Invite by email from the website's Team page, they receive an email to join
Adding a document to a team
- From the documents's Team section in the desktop app, choose your team
- The document is automatically reencrypted under the team's shared key so any member can open it
- Every synced evidence image and generated PDF for that document now counts against the team's pooled storage instead of personal storage
Handing a document off
- Only one member can edit a document at a time, the desktop Team screen shows who, and since when
- All memebers can add artifacts to a team document
- Use "Transfer" to pass it to someone else for cowriting or senior review
- If you're waiting on a document, "Request" it to notify whoever's currently holding it
- The team leader can reclaim a document at any time; any active member can reclaim it once it's been idle for 2 hours
Storage & Billing
What counts
- Only documents you choose to sync to the cloud use any storage, local only work never counts against anything
- Storage covers documents and artifact text, evidence images, and generated PDFs
Free
- Unlimited local desktop usage, no credit card required, no cloud storage
- A ThreatDoc account is not required to sign in to the desktop application
Basic
- 1 GB of encrypted cloud storage for your own documents
- Sync documents across your own devices
Pro
- 5 GB per active team member, pooled across everything the team owns, not a separate bucket per person
- $20/mo per seat after the first
- Team management and documents hand off
Over your limit
- New evidence uploads are declined once you're at your limit, with a message showing current usage
- Nothing already synced is deleted, free up room by removing evidence you no longer need, or upgrade
Folders
A folder is encrypted container for files since exported files are not encrypted on the drive.
Creating a folder
- From the Folders screen, create a folder and give it a name
- Each folder uses a key derived from your account key the same way a document is
- Add or export files from inside the folder
Desktop shortcut
- Create a desktop shortcut for a folder to open it directly, without going through the main app window first
- Drop a file onto that shortcut's icon and it's imported and encrypted automatically
- If you do not see the shortcut, press F5 on your actual desktop to refresh
Local only, for now
- Folders live on this device only, they don't sync to the cloud or across devices yet
- Deleting a folder removes it and everything in it from this device, this can't be undone