Observable enrichment in MISP
By enriching observables with additional information from various MISP sources during incident response investigations, you can contain identified threats.
Enable automatic observable enrichment in MISP
Enable automatic observable enrichment in the ServiceNow AI Platform MISP when new observables are associated with the security incident.
Avant de commencer
- Enable the Security Incident Response system property for the Enables or Disables the scheduled job, Lookup Security Incident Observables option to trigger the observable enrichment capability in SIR.
- Role required: sn_si.analyst
Procédure
Perform a manual observable enrichment in MISP
Select individual or multiple observables and perform a manual observable enrichment so that you can enrich observables with additional information from various MISP sources.
Avant de commencer
- Review the MISP user role and permissions for using the MISP bi-directional features.
- Role required: sn_si.analyst
Procédure
Add or remove tags to MISP attributes
Add or remove tags in MISP to classify events or attributes. You can use tagging globally to enable your classification or use tags locally when you don't want MISP events to be modified during your classification.
Avant de commencer
- Review the MISP user role and permissions for using the MISP bi-directional features.
- Verify that the attribute that you are editing belongs to the same organization as the MISP user.
- Note that the tags and galaxies that are available to you are based on the MISP source and its distribution permissions.
- Role required: sn_sec_misp.write
Procédure
- Tags (Local)
- Tags (Global)
Add or remove galaxies to a MISP event or attribute
Add or remove galaxies in MISP so that you can classify these objects as a cluster in MISP and attach them to MISP events or attributes.
Avant de commencer
- Review the MISP user role and permissions for using the MISP bi-directional features.
- To add local galaxies, the user who has configured the integration should belong to the host organization of the corresponding MISP server.
- Note that the tags and galaxies that are available to you are based on the MISP source and its distribution permissions.
- Role required: sn_sec_misp.write
Procédure
- Galaxies (Local)
- Galaxies (Global)
Résultats
Add comments to MISP attribute
Add comments for the MISP attributes. The comments that you add are for informational purposes only and are not used for correlation of MISP data.
Avant de commencer
- Review the MISP user role and permissions for using the MISP bi-directional features.
- Verify that the attribute that you are editing belongs to the same organization as the MISP user.
- Role required: sn_sec_misp.write