Enrichment

Summary

One part that consumes lots of security analyst’ time is to bring more information about atomic alerts. DTonomy’s built in integrations with different data sources enable you to quickly enrich your alerts with extra information that can help you determine right actions for your security alerts.

Alert Score

DTonomy AIR assignes score for each ingested alert. The score can be either assigned manually by the user or it can be determined by the DTonomy AI The score is a decimal number btween 0 and 1 with 1 to be most likely positve alarm that need to be investigated immediately, and 0 to be likely false alarm which can be processes with lower priority or ignored.

Manually assign alert score

DTonomy workflow user can assign the alert score manually when upload alerts to the DTonomy platform. The user can set msg.score in a function node right before using the advanced data upload node. DTonomy AIR will set the alert score to be this msg.score value

Automatically assign alert score

If a user does not set the alert score manually during the alert upload, the DTonomy AI will kick in to decide the score of each alert uploaded. Based on the alert context, the DTonomy AI engine will select the risk model that most fit the alert and give an accurate prediction of the alert score.

Network Information

ASN

Query a given IP for autonomous system information

_images/asn.png

DNS resolver

Resolve a host name to a list of ips

_images/dnsresolver.png

IpGeo

Decode Geo information for an IP

_images/IpGeo.png

Ip Reputation

Retrieve reputation for a given IP via Minemeld

_images/ipReputation.png

Nmap

Scan network to find live hosts on the network

_images/nmap.png

Nslookup

Given a domain name, output a list of URLs

_images/nslookup.png

Whois

Retrieve whois information for an ip or host

_images/whois.png

Threat Intelligence

VirusTotal

We support multiple integrations with Virustotal to collect intelligence.

_images/virustotal.png

Shodan

Check Ip via shodan.

_images/shodan.png

Anyrun

Retrieve malware analysis results from anyrun

_images/anyrun.png

HaveIBeenPwned

Examine whether a user’s email or password is compromised or not.

_images/haveibeenpwned.png

Hybrid Analysis

Check Ip, url information from Hybrid Analysis

_images/hybridanalysis.png

Vulnerability

CVE

Quickly query national vulnerability database for CVE information

_images/cve.png

Nexpose

Query Rapid7 Nexpose for existing vulnerability information

_images/nexpose.png

Appspider

Query Rapid7 Appspider for existing vulnerability information

_images/appspider.png

Raw Logs

Similar to data ingestion, you can connect to those data sources for raw logs for enrichment.

System Information

It is common to query system information for enrichment.

LDAP

Query ldap for more user information to enrich your alerts.

_images/ldap.png

SCCM

Query SCCM information via simple integrations.

_images/SCCM.png