Chapter 11: Enriching Data to Make Intelligence
In Chapter 1, Introduction to Cyber Threat Intelligence, Analytical Models, and Frameworks, we discussed the intelligence pipeline and the process of making data into intelligence through analysis, production, context, and enrichment. Enrichment is one of the final steps in transitioning collected data into something that can be actioned for further hunting or defensive considerations by the incident response teams.
In this chapter, you will learn how to use various tools to enrich both local observations and threat information to add contextually relevant information to events in their journey to actionable intelligence.
In this chapter, we're going to cover the following main topics:Â
- Enhancing analysis with open source tools
- Enriching events with third-party tools
- Enrichments within Elastic