Use PDIs? Take our 5-minute survey to help shape the PDI roadmap.

Threat Intelligence vs Enrichment of an SIR

SRIRAMSANKAR007
Tera Contributor

Hii guys!!

My doubt is what is the primary difference between Threat Intelligence and Enrichment. I know that Threat Intelligence is one of the type of Secops Component. And Enrichment is like to enchance the data's information. But what my thing is as there is Threat intelligence, then what is the purpose of Enrichment?

And give me some idea on how to use the Enrichement in SIR?

1 ACCEPTED SOLUTION

abirakundu23
Giga Sage

Hi @SRIRAMSANKAR007,

The primary difference is:

  • Threat Intelligence helps identify whether an observable (IP, URL, domain, hash, etc.) is associated with a known threat.
  • Enrichment adds additional context/information about that observable or security incident to support investigation.

A good practical example is Observable Enrichment in SIR, where ServiceNow can enrich an observable associated with an incident and display the enrichment results in the incident's Indicators/Investigation area.

Automatic Execution: Configure enrichment workflows or capability implementations so that whenever a new observable (e.g., an IP or domain) is added to a Security Incident, background jobs query configured tools automatically.

Manual Triggering: Analysts can navigate to the Observables related list within a Security Incident, select an observable, and click Run Enrichment (or select specific capabilities like WHOIS lookup).

Please mark helpful & correct answer if its worthy for you.

 

View solution in original post

1 REPLY 1

abirakundu23
Giga Sage

Hi @SRIRAMSANKAR007,

The primary difference is:

  • Threat Intelligence helps identify whether an observable (IP, URL, domain, hash, etc.) is associated with a known threat.
  • Enrichment adds additional context/information about that observable or security incident to support investigation.

A good practical example is Observable Enrichment in SIR, where ServiceNow can enrich an observable associated with an incident and display the enrichment results in the incident's Indicators/Investigation area.

Automatic Execution: Configure enrichment workflows or capability implementations so that whenever a new observable (e.g., an IP or domain) is added to a Security Incident, background jobs query configured tools automatically.

Manual Triggering: Analysts can navigate to the Observables related list within a Security Incident, select an observable, and click Run Enrichment (or select specific capabilities like WHOIS lookup).

Please mark helpful & correct answer if its worthy for you.