Perform Run Sighting Search related integration.
Before you begin
Role required: sn_sec_tisc.admin
To perform this action select the implementation and add common run time inputs that apply for all the selected implementations as applicable.
Procedure
-
Navigate to .
-
Click Threat Analyst Workbench icon.
-
Go to .
-
Open any observable record.
-
Click Run Sighting Search.
The Run Sighting Search
Select Implementations modal screen is displayed.
Note: The Run Sighting Search performs the threat intelligence lookups to determine whether the observables are associated
with any known threats.
-
Select the required implementation(s) from the list.
-
Click Next.
-
Select the common run time input value such as Select Date/Time frequency and Number of hours.
-
Click Submit.
The selected enrichment action will be executed and an information message is displayed that
Run Sighting Search execution has started.Note:
- Once the execution initiated or completed, a work notes is posted on the activity stream of the form view.
- The enrichment results pushed from SIR workspace can be found in the Enrichment Results tab of that corresponding Observables details page in TISC Workspace.
- The enrichment results pushed from SIR workspace can be identified using Source field of the enrichment result table.