Solutions and Applications
SOC Solutions Bundle
Configure-threat
1 min
configure threat intelligence enrichment integration threat intelligence enrichment gathers reputation information from observables, such as ip addresses, domains, urls, hashes, email addresses, and so on from one or more enrichment providers using enrichment components results are aggregated in threat intelligence records, and displayed in case and incident management records as well every observable type has a primary intelligence provider (pip) docid\ bbcgtaqyctwozro7p0x5m , which is the canonical source of truth for reputation verdict, permalinks, and so on for that observable type navigate to components open the soc enrich observable component edit the components under the parallel node remove any enrichment sources you are not using add new enrichment sources from the components menu click "edit" and map in "inputs observable" as a playbook property for each new enrichment source after removing or adding new enrichment sources, edit the aggregate enrichments action to reflect the changes you have made each component's enrichments property should be mapped to an append action in the aggregate enrichments action ensure that your enrichment assets are configured on the assets page