Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

In previous article of the sereiesseries, Enriching Telemetry Events, we walked through how to enrich a domain element of a given telemetry event with WhoIs data like home country, company associated with domain, etc. In this article, we will enrich with a special type of data called threat intel feeds. When a given telemetry event matches data in a threat Intel feed, an alert is generated.

...