Automated IOC Enrichment
Learn how to automate enrichment of IOC’s using flows when they match a certain criterion.
Before you begin
Role required:
- System Administrator (view, create or edit)
- sn_sec_tisc.admin (view)
About this task
Automate enrichment of IOC’s triggers only when:
- the type of the observable is a domain name, IPv4 address, or IPv6 address.
- the observable is in a processed state.
- the observable does not have the tags enriched or Skip Enrichment.
Procedure
Navigate to All > Threat Intelligence Security Center > Administration.
Select Automated Flows.
Select Automated IOC Enrichment action link to view the respective rule details in the flow designer.
View the flow designer action for the following trigger:
Observable Updated where (Type is Domain Name, or Type is IP address (V4), or Type is IP address (V6); and Processing Status is Processed; and TISC Tags does not contain Enriched, or TISC Tags does not contain Skip Enrichment, or TISC Tags does not contain Potential New Threat)If the observable is an IPv4 or IPv6 address and it falls within an allowed CIDR range, then:
Add the observable to Allow List.
Update the observables tags to Skip Enrichment.
End the flow for this observable.
Else, enrich the observable data with available capabilities:
Perform threat lookup and sighting search to gather additional information about the observable.
Update the observable with enriched data.
Add a tag Enriched to indicate that the IOC has been processed.
Also, if the observables reputation is clean, then:
- Mark observable as false positive and inactivate.
Else, if observable reputation is unknown
- Add tag Not Potential Threat & Enriched to indicate that it is not a threat.
Automated IOC Enrichment in TISC.
Parent Topic:Working with automated flows
Related topics
Automated sharing of high-risk IOC's with trusted partners
Automatically add threat intelligence to a TAXII collection
Create vulnerability assessment for zero day
Analyze, assess, and disseminate observables
Analyze and assess threat IoC’s
Vulnerability Management Support
Zero-day vulnerability tracking