Skip to content
Release: Australia · Updated: 2026-04-27 · Official documentation · View source

Configure new enrichment

Set up threat intelligence enrichment integrations to automatically gather additional context about observables, search for sightings, or perform threat lookups from external security vendors.

Before you begin

Role required: sn_sec_tisc.admin

Procedure

  1. Navigate to Workspaces > Threat Intelligence Security Center.

  2. Select the Integrations icon.

Image omitted: enrich-all-integrations.png
Configure new enrichment from All Integrations viewIn the **All Integrations** section, select the **Configure new enrichment** action.
  1. Choose an enrichment type from the Configure new enrichment dialog.

    The Configure new enrichment dialog displays three enrichment types: Observable Enrichment, Sighting Search, and Threat Lookup.

Image omitted: enrich-popup-observables.png
Configure the enrichment type
  1. From the enrichment types, select your preferred option and select Next.

    The system displays available integrations.

  2. Select an integration from the list of available integrations.

    The system opens the Create Enrichment Integration page with pre-filled details for the selected integration, such as WHOIS integration.

  3. Complete the Create Integration form fields.

FieldDescription
NameName for the new enrichment integration. For example, `WHOIS1`.
Vendor NameName of the vendor. This field is automatically populated. For example, `WHOIS`.
Integration TypeType of integration selected, such as Observable Enrichment. This field is automatically populated.The following Integration Types are supported: - Observable Enrichment - Sighting Search - Threat Lookup
DescriptionUnique description for the new enrichment integration.
  1. In the Integration Configuration section, configure the integration details.

    The Integration Configuration section includes details such as API key, API Client ID or secret, username, and password. These details vary for different integrations.

  2. To create the enrichment integration configuration, select Save.

    The system validates the provided details and sets the enrichment integration status to inactive by default.

  3. To store the integration configurations as draft only, select Save as Draft.

    You cannot enable an integration when it is saved as draft. If you're not sure about the configuration details, you can use the Save as Draft option. After you get the configuration details, you can complete the draft version and create it.

  4. To enable the enrichment integration, select Enable.

    The integration status changes to enabled.

    Note: You can also enable, disable, or delete an enrichment integration using the Actions menu on the integration tile.

Parent Topic:TISC Enrichment integrations

Related topics

TISC Security Tools integrations