View Enrichment Results
TISC context facilitates viewing threat intelligence data such as observables within the security incident response workspace.
Security analysts can detect, investigate, and respond to security incidents more effectively from the workspace.
TISC Context in Security Incident Response Workspace allows security analysts to add security incidents or observables to TISC cases directly from the workspace. You can also view enrichment results and observables related information such as threat actors, attack patterns, and campaigns.
Using this section, you can do the following:
- Associate observables to a TISC case.
- View associated observables information.
- View observables enrichment results.
Observable Information
| Type | Description |
|---|---|
| Sightings | Lists all the associated sightings for selected TISC observables. |
| Observable Enrichment Results | Lists all the associated observable enrichment results for selected TISC observables. |