A SIEM can be powered by Threat Intelligence feeds.

These streams may contain, for example:

  • malicious IP addresses;
  • suspicious domains;
  • malicious URLs;
  • hashes;
  • indicators of compromise;
  • information on certain campaigns;
  • information related to attacker groups.

Suppose an internal workstation contacts an IP address.

The SIEM can compare this address with an information database.

If it corresponds to a known indicator, the event can be enriched.

We then obtain:

“Station X communicated with address Y, which is currently associated with malicious activity according to [source].”

The context immediately becomes more usable.

However, caution is advised: Threat Intelligence is not an absolute truth. Data flows must be assessed, contextualized, and adapted to the actual risk of the business.

Categories: