- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
yesterday
Hii guys!!
My doubt is what is the primary difference between Threat Intelligence and Enrichment. I know that Threat Intelligence is one of the type of Secops Component. And Enrichment is like to enchance the data's information. But what my thing is as there is Threat intelligence, then what is the purpose of Enrichment?
And give me some idea on how to use the Enrichement in SIR?
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
yesterday
Hi @SRIRAMSANKAR007,
The primary difference is:
- Threat Intelligence helps identify whether an observable (IP, URL, domain, hash, etc.) is associated with a known threat.
- Enrichment adds additional context/information about that observable or security incident to support investigation.
A good practical example is Observable Enrichment in SIR, where ServiceNow can enrich an observable associated with an incident and display the enrichment results in the incident's Indicators/Investigation area.
Automatic Execution: Configure enrichment workflows or capability implementations so that whenever a new observable (e.g., an IP or domain) is added to a Security Incident, background jobs query configured tools automatically.
Manual Triggering: Analysts can navigate to the Observables related list within a Security Incident, select an observable, and click Run Enrichment (or select specific capabilities like WHOIS lookup).
Please mark helpful & correct answer if its worthy for you.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
yesterday
Hi @SRIRAMSANKAR007,
The primary difference is:
- Threat Intelligence helps identify whether an observable (IP, URL, domain, hash, etc.) is associated with a known threat.
- Enrichment adds additional context/information about that observable or security incident to support investigation.
A good practical example is Observable Enrichment in SIR, where ServiceNow can enrich an observable associated with an incident and display the enrichment results in the incident's Indicators/Investigation area.
Automatic Execution: Configure enrichment workflows or capability implementations so that whenever a new observable (e.g., an IP or domain) is added to a Security Incident, background jobs query configured tools automatically.
Manual Triggering: Analysts can navigate to the Observables related list within a Security Incident, select an observable, and click Run Enrichment (or select specific capabilities like WHOIS lookup).
Please mark helpful & correct answer if its worthy for you.