Summary
In this chapter, we tried to demonstrate the importance of intelligence enrichment and analysis during the analysis phase of the intelligence life cycle. While sometimes complex, threat intelligence enrichment plays a vital role in producing accurate and actionable threat intelligence for other teams to leverage and help enable tactical and strategic decision-making. Hopefully, you now have a rudimentary understanding of the importance of intelligence analysis and enrichment as it pertains to files and, more specifically, infrastructure.
First, we dove into infrastructure and file-based analysis, as well as some common techniques that are used to analyze each. While not an exhaustive list of processes, this chapter should have served as a good introduction to intelligence enrichment and some individual concepts you should examine closely. While there's no one single tool to perform intelligence enrichment and analysis, there are several paid-ror and open source options...