Run Enrichment operations in TISC
The following table below describes the interactions involved in running different enrichment operations from TISC.
TISC modal screens
| Capability | UX Frameworks interactions | Integrations supported |
|---|---|---|
| Run Threat Look Up | On Screen 1 – Select the implementation\(s\) and submit.There are no common inputs or implementation specific inputs applicable for Run Threat Look Up. | - Virus Total - Crowd Strike Falcon Intelligence |
| Run Sighting Search | Screen 1 – Select Implementations and Screen 2 – Common Inputs are applicable.Sighting search takes date and time frequency as common inputs across multiple implementations of Splunk and other integrations. | - Elastic search - Splunk Sighting |
| Run Observable Enrichment | Only Screen 1 – Select Implementations.There are no common inputs or implementation specific inputs applicable for Run Observable Enrichment. | - WHOIS - Shodan |
- Observable Enrichment
The Enrich Observable WhoIs workflow performs enrichment on selected observables. If the observables are of a type recognized by the WhoisXML API Integration, the observables are enriched. - Run Threat Lookup
Select one or more implementations as applicable to run threat lookup on observables. - Run Sighting Search
Perform Run Sighting Search related integration. - Run Observable Enrichment
Select one or more implementations as applicable to run threat lookup on observables.
Parent Topic:Observables