Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Run Enrichment operations in TISC

The following table below describes the interactions involved in running different enrichment operations from TISC.

TISC modal screens

CapabilityUX Frameworks interactionsIntegrations supported
Run Threat Look UpOn Screen 1 – Select the implementation\(s\) and submit.There are no common inputs or implementation specific inputs applicable for Run Threat Look Up.- Virus Total - Crowd Strike Falcon Intelligence
Run Sighting SearchScreen 1 – Select Implementations and Screen 2 – Common Inputs are applicable.Sighting search takes date and time frequency as common inputs across multiple implementations of Splunk and other integrations.- Elastic search - Splunk Sighting
Run Observable EnrichmentOnly Screen 1 – Select Implementations.There are no common inputs or implementation specific inputs applicable for Run Observable Enrichment.- WHOIS - Shodan
  • Observable Enrichment
    The Enrich Observable WhoIs workflow performs enrichment on selected observables. If the observables are of a type recognized by the WhoisXML API Integration, the observables are enriched.
  • Run Threat Lookup
    Select one or more implementations as applicable to run threat lookup on observables.
  • Run Sighting Search
    Perform Run Sighting Search related integration.
  • Run Observable Enrichment
    Select one or more implementations as applicable to run threat lookup on observables.

Parent Topic:Observables