# Threat Center The **Threat Center** in the sidebar shows the security findings of **every host in your account** in one ranked list, instead of one server at a time. Use it to answer "where should I start today?" across a fleet, then open the host that needs work. The per-host view is the [Threat Center tab](hosts/threat-center.md) on a host. That page explains what each finding type means, what its scores say about how urgent it is, and how to decide what to fix first. This page only covers what is different about the account-wide view. ![The account-wide Threat Center with the severity filters, the search box and the findings list|1000](../assets/screenshots/platform/threat-center_overview.png) ## What it covers The list includes every host you have access to in the current account. Hosts that belong to a [cluster](clusters.md) are not listed here: a cluster has its own Threat Center on the cluster page, where each finding keeps the member it was found on. Findings are ranked by risk across the whole account, so the most urgent finding on any host is at the top. Above the list, a counter per severity band - Critical, High, Medium, Low and Info - shows how many findings the account holds in that band. Selecting a band narrows the list to it. > [!NOTE] > A large account can hold far more findings than a page can show. The list is a ranked top: it gives > you the findings that matter most, not a complete inventory. Open a host's own > [Threat Center tab](hosts/threat-center.md) to work through everything on that server. ## Finding what you need - **Search** - one box over the host name, the vulnerability identifier, the package and the rule name. Use it to answer "is this vulnerability anywhere in my account?" or "which servers still run this package?". - **Severity counters** - select a band to narrow the list to it. - Each finding names the **host** it was found on, next to the package and the file path, so you can go straight to the right server. The three panels are the same as on a host: **Vulnerabilities**, **Indicators of Compromise** and **Runtime Detections**. Each says so plainly when it is empty, rather than showing an empty box. ## What you can do here - **Export** on a panel downloads its current list as a CSV file, for example to share with a developer. - **Rescan** starts a fresh scan: one host, or every host that reports. - The **TurboStack Connector** status shows each host's heartbeat and when its last scan finished. A host reporting `no signal yet` is not sending results; if that persists, [contact support](support.md). Dismissing a finding and clearing a list are **not** available on the account-wide page. Those act on one server, so you do them on that host's [Threat Center tab](hosts/threat-center.md). ## Related - [Threat Center (per host)](hosts/threat-center.md) - the finding types and what the scores mean - [Security overview](../concepts/security-overview.md) - how the protection layers fit together - [Security (host configuration)](hosts/security.md) - [Health](monitoring.md) - availability and performance, rather than security - [Clusters](clusters.md)