The need and motivation for enrichment and analysis
For threat intelligence and security teams to successfully sift through the mountains of data that is often generated from an organizational environment, CTI and security functions need to examine enriched or contextualized data to action their workflows and understand the attack itself. This need is often achieved through an enrichment process, or the act of adding contextualization to specific data, making it more actionable.
Threat intelligence enrichment or analysis is the process of appending or enhancing the relevant context for data and, more specifically, threat intelligence data. Additionally, enrichment encompasses normalization processes for processing CTI data, such as deduplication. CTI functions aren't the sole beneficiary of enriched threat intelligence. Many additional teams outside of threat intelligence can benefit from enrichment, such as incident response, forensics, network security, Security Operation...