Analyze and assess threat IoC’s
Learn how to analyze an IOC’s which are a threat and notifying the security incident team.
Before you begin
Role required:
- System Administrator (view, create or edit)
- sn_sec_tisc.admin (view)
About this task
Whenever a sighting search enrichment is requested:
- if the observable is sighted (count > 0) and
- Observable Reputation is Malicious and
- Observable Threat score is > 80 and
- Observable Confidence > 80