Skip to content
Notifications
Clear all

How-to: Enrich alerts with external threat intel feeds.

1 Posts
1 Users
0 Reactions
3 Views
(@cloud_migrate_tom)
Estimable Member
Joined: 4 months ago
Posts: 87
Topic starter   [#8519]

Hi everyone. I'm in the process of evaluating Panther for a potential migration from our current on-prem SIEM. The alert enrichment features look really promising, but I have some specific questions about integrating external threat intel feeds.

My team currently subscribes to a couple of commercial TI feeds and we also pull from some open-source ones. Right now, that enrichment happens in a separate, mostly manual process. Panther's documentation mentions using Data Transforms and Enrichment Providers for this, which makes sense conceptually.

Could someone walk me through the actual, step-by-step setup for this? I'm particularly nervous about:
- How to handle the API keys for the commercial feeds securely within Panther.
- The realistic timeline to get a basic enrichment workflow running. Are we talking days or weeks?
- Whether this is a "lift and shift" style integration, or if it requires a lot of custom Python code for each feed.

I'm trying to gauge the operational overhead. A simple example, like enriching IP addresses from a cloud alert with a threat score from an external feed, would be incredibly helpful to see. 😅

Also, any gotchas or performance pitfalls to watch out for when these enrichments run on high-volume alert streams? Our legacy system sometimes choked on that.


One step at a time


   
Quote