After you configure integration between Kaspersky Next XDR Expert and Kaspersky TIP, you can obtain information about the reputation of observables related to an alert or incident from Kaspersky TIP or Kaspersky OpenTIP, and then enrich the obtained data.
You can obtain information only for observables with the following types: domain, URL, IP, MD5, SHA256.
You can configure data enrichment to run automatically. To do this, when creating or editing a playbook, in the Algorithm section you must specify the following:
You can specify one of the following services:
You can specify one of the following values:
This value is set by default.
In the playbook algorithm, you can use the output enrichment parameters that are displayed in the fields that Kaspersky TIP returns.
You can view the enrichment result for all observables related to an alert or incident in one of the following ways:
To view an enrichment result:
You can also obtain the information from Kaspersky TIP, and then enrich data manually on the Observables tab in alert or incident details.
Page top