Enrichments within Elastic
The Elastic Security app currently has IP reputation links that can be used to gain additional information about threat detections. To use these, simply click on an IP address of interest from within a timeline to be sent to either VirusTotal or Talos Intelligence and automatically perform a search for the IP address. Additional indicator types will hopefully be added in the future:
Figure 11.11 – IP reputation checking from within Elastic
In the preceding screenshot, you can see the IP address 64.225.18.241 has been identified in a timeline. From here we can click on the IP address and the network details flyout pane has hyperlinks that we can click on for VirusTotal and Talos Intelligence that will provide us with additional enrichments on this IP address.
In this section, we saw how we can use the timeline feature of the Elastic Security app to perform enrichments for IP addresses.