Intelligence Objects Event Category
7 min
an intelligence object is a threat intelligence entity surfaced in the intelligence browser docid 05uqcn5rinzdxddsrktmy it is a structured record of something known to matter in a threat context an indicator of compromise, a malware family, a named campaign, a vulnerability, a threat actor, or a piece of adversary infrastructure the intelligence object category connects the objects in the intelligence browser to your identifiers and your tenant feed when enabled on an identifier, a match against an intelligence object surfaces an event in your feed, so exposures flagged by third party risk lists appear alongside your other events intelligence objects are also available through the flare api https //api docs flare io/api reference/tokens/endpoints/generate using the intelligence object event type on the tenants , identifiers , and identifier groups endpoints viewing intelligence object events intelligence object events can be viewed either in global search or in the tenant feed by selecting the intelligence objects event type event details each intelligence object event includes the following data summary the summary tab shows the event severity, metadata showing the object type, source, provider and relevant dates a confidence score is also included from each of the sources click view to see additional details about the intelligence object severity the severity tab shows how the event was scored and which severity rules were applied every event in this category is assigned an initial severity of \<font color="#f97316">`high`\</font> to change the severity for these events, you can create a custom severity rule or change the severity of the default flare rule see severity rules docid\ ltsdxtp9ncx7 fohtdsmk for details advanced the advanced tab provides complete raw data for the event for additional investigation configuration follow these steps to get full value from the intelligence objects surfaced for your organization select the intelligence object category for an identifier the intelligence object category is enabled during identifier configuration create a new identifier or edit an existing one select intelligence object as one of the categories use severity filters to define which severities to include for this identifier all intelligence object events are assigned an initial severity of \<font color="#f97316">`high`\</font> to customize severity classification, see severity rules docid\ ltsdxtp9ncx7 fohtdsmk optionally, use add to group to organize the identifier alongside related assets configure alerting once the identifier is set up, use alert central docid\ eqfosnlszdt49 kdw6xts to send alerts to the right stakeholders create a new alert, and set the identifier scope to the identifier created for intelligence objects under categories , select intelligence object use severity filters to restrict the alert to the severities that warrant interruption configure time settings to control alert frequency and timing select an alert channel for delivery take action from the tenant feed, you can act on an event using the following actions mark as remediated indicate that the exposure has been addressed ignore remove the event from your active feed when it is not relevant to you edit modify the event's classification add to report include the event in a report for internal or client facing distribution building an investigation workflow an intelligence object event serves as the entry point for an investigation rather than the conclusion the value comes from what you do next, which is confirming the match, understanding the threat behind it, and responding appropriately the steps below cover two workflows, one that uses the cyber threat intelligence (cti module) docid\ rrhh7 7ulnlxqtkg ijtc and one that works from the tenant feed alone triage in the tenant feed confirm which identifier matched and how critical the match is use the object confidence score to weigh your response a high confidence match supported by strong evidence supports faster action than a low confidence one pivot to the intelligence browser view the intelligence object in the intelligence browser docid 05uqcn5rinzdxddsrktmy to see additional details about iocs, malware families, threat actors, campaigns, and intrusion sets open the matched intelligence object to see its sources, metadata, and relationships to other objects this is where you learn whether the indicator is tied to an active campaign, known malware, or an attributed actor act and close the loop take the appropriate action in your environment, then use mark as remediated or ignore in the feed so your team has an accurate picture of what has been handled triage in the tenant feed confirm which identifier matched and how critical the match is use the object confidence score to weigh your response a high confidence match supported by strong evidence supports faster action than a low confidence one act and close the loop take the appropriate action in your environment, then use mark as remediated or ignore in the feed so your team has an accurate picture of what has been handled