Use this section to understand how enrichments actions are performed on case(s).
Before you begin
Role required: sn_sec_tisc.admin
Procedure
-
Navigate to .
-
Click Threat Analyst Workbench icon.
-
Go to .
All the cases are displayed.
-
Select any case or case task.
-
Go to Artifacts tab.
-
Select the Observables related list.
-
Select one ore more Observables.
-
Click any Enrichment actions from the dropdown list.
-
Select the available implementation(s).
-
Click Submit.
For example, Run Threat Lookup. The selected enrichment action will be executed and an information message is displayed that
Observable enrichment execution has started on the selected observable(s). Results
will be available in the detail page of respective observable(s) once the execution is complete.
Note: Once the execution initiated or completed, a work notes is posted on the activity stream of the form
view.
