There are two ways to get to Threat Explorer. First, when you click a hyperlink in any of the Dashboard security monitors, you will be directed to the Threat Explorer page with the core attribute and admin domain already set. The second way is to navigate to Analysis → <Admin Domain Name> → Threat Explorer.
Dashboard workflow
See section Threat Explorer to understand the dashboard workflow to Threat Explorer.
Threat Explorer workflow
When you navigate to Analysis → <Admin Domain Name> → Threat Explorer, you can set the filter based on your needs. The page displays the default top N security tables and root admin domain, which includes data from the child domains also. No filter criteria is set at this point of time.