216.73.216.233

Enrichment Data: Keeping it Fresh

· Published 09/09/2024 07:38 · Modified 09/09/2024 07:50

Export JSON

Essential information

Published
09/09/2024 07:38
Modified
09/09/2024 07:50
Tags
2024-09-09 data enrichment threat intelligence
Related entities
5 observables, 6 techniques (mitre)

Description

The article discusses the importance of keeping enrichment data up-to-date for analyzing honeypot attacks. Various sources like Internet Storm Center, URLhaus, SPUR, and VirusTotal are used to enrich data collected from honeypots. The author examines how frequently this data changes and its accuracy over time. VirusTotal data shows that it can take months for a significant increase in malicious hits for a given file hash. URLhaus data demonstrates how the number of reported URLs for an IP address can change rapidly. SPUR data, which provides WHOIS information, shows that while most IP addresses maintain consistent information, some experience frequent changes in organization or location details. The article emphasizes the need for regular updates and the use of multiple enrichment data sources for accurate threat analysis.

External references