A SIEM can be powered by Threat Intelligence feeds.
These streams may contain, for example:
- malicious IP addresses;
- suspicious domains;
- malicious URLs;
- hashes;
- indicators of compromise;
- information on certain campaigns;
- information related to attacker groups.
Suppose an internal workstation contacts an IP address.
The SIEM can compare this address with an information database.
If it corresponds to a known indicator, the event can be enriched.
We then obtain:
“Station X communicated with address Y, which is currently associated with malicious activity according to [source].”
The context immediately becomes more usable.
However, caution is advised: Threat Intelligence is not an absolute truth. Data flows must be assessed, contextualized, and adapted to the actual risk of the business.