Threat Intelligence Manager (TIM) Investigation enrichment with Cisco Talos Intelligence

Cisco Talos Intelligence enriches Splunk Enterprise Security investigations through TIM Cloud by adding threat context for supported observables, while remaining separate from ES Native threat intelligence workflows.

Note: Splunk Threat Intelligence Management (Cloud), also known as TIM Cloud, adds additional threat context to observables in a Splunk Enterprise Security investigation with Talos Intelligence integrated into TIM Cloud. Talos enrichment, as part of TIM Cloud, is available only when TIM Cloud is enabled for the Splunk Enterprise Security environment.

Use Talos enrichment to review reputation and classification information for observables without leaving the investigation workflow. The returned context can help an analyst assess a threat, prioritize work, and decide on the next investigative or response action.

How automated Talos enrichment in TIM works

Beginning with Splunk Enterprise Security 8.4, Cisco Talos data is available on the Intelligence tab of an investigation. When the investigation requests Talos enrichment, Enterprise Security sends eligible observables to the TIM Cloud enrichment service. TIM Cloud requests Talos context and returns the results to the investigation.

The TIM Cloud implementation supports the following behavior:

  • Enrichment is scoped to an authenticated tenant and an investigation request.
  • A single request can contain up to 20 observables.
  • Supported observable types are IP address, domain, URL, and SHA-256 file hash.
  • Successful results can include Talos taxonomy context tags, including taxonomy and entry names and, when available, an external identifier such as a MITRE ATT&CK technique or CVE (Common Vulnerabilities and Exposures).
Note: The observable types that appear in the user interface depend on the observables attached to the investigation and the Enterprise Security version. The TIM Cloud service supports the types listed above, but an investigation might not contain every type.

Talos provides additional context. A Talos result does not by itself determine whether an observable or investigation is malicious. Review Talos context together with the finding evidence, other intelligence sources, and your organization's investigation procedures.

Requirements

Confirm the following requirements before using Talos enrichment in an investigation:

  • Splunk Enterprise Security 8.4 or higher is deployed.
  • TIM Cloud is licensed, provisioned, and enabled for the environment.
  • At least one TIM Cloud source is active and at least one threat list exists so that the investigation Intelligence tab is available. For details, see Activate an intelligence source and Configure threat lists in Splunk Enterprise Security.
  • The investigation contains an eligible observable.
Note:

Talos enrichment in an investigation does not work when TIM Cloud is not enabled.

Talos is implemented through the TIM Cloud service; it is not an ES Native lookup.

Review Talos intelligence in an investigation

  1. In Splunk Enterprise Security, open Mission Control.
  2. Open an investigation that contains an IP address, domain, URL, or SHA-256 file hash observable.
  3. Select the Intelligence tab.
  4. Select or review the eligible observable or observables.
  5. Review the Cisco Talos context returned for each observable.
  6. Compare the Talos classifications and external references with the findings and other threat intelligence in the investigation.

The Talos result can include classification context such as Acceptable Use Policy categories, threat categories, MITRE ATT&CK references, or other taxonomy tags. If Talos has no enrichment for an observable, the investigation does not display Talos context for that value.

How Talos relates to TIM Cloud and ES Native

Enterprise Security provides two threat intelligence paths:

  • TIM Cloud is the cloud-hosted Threat Intelligence Management service used for investigation intelligence, threat lists, and cloud-hosted intelligence sources.
  • ES Native is the threat intelligence capability stored and processed in the Splunk Enterprise Security deployment. It uses local threat-intelligence KV Store collections and ES Native threat-matching searches. ES Native was formerly known as Threat Intelligence Framework (TIF).

Talos Investigation enrichment has a direct relationship with TIM Cloud and no direct relationship with ES Native.

Capability Talos relationship Result
TIM Cloud

Direct

The Investigation experience calls a Talos enrichment endpoint in the TIM Cloud service.

Talos context appears with eligible observables in the investigation Intelligence tab. TIM Cloud must be enabled.
ES Native

None for the built-in Investigation enrichment experience

The Talos response is not automatically written to ES Native threat-intelligence KV Store collections.

Talos does not become an ES Native feed and does not participate in ES Native threat-matching searches through this workflow.
TIM Cloud sources and threat lists Talos enrichment is a TIM Cloud-backed capability that is automatically enabled when TIM is enabled. It does not require any additional configuration, so it is not listed on the TIM Cloud Data Sources page. Do not expect a Talos source subscription or Talos threat list to appear on the TIM Cloud data-sources page.
Enterprise Security investigation

Direct

Enterprise Security presents the context returned by TIM Cloud in the investigation workflow.

Analysts can use Talos context without leaving Mission Control.

The built-in enrichment is a query-based service interaction. It does not continuously ingest a Talos feed into TIM Cloud or ES Native.

Additional Cisco Talos apps on Splunkbase

Splunkbase provides a separate Cisco Talos Intelligence for Enterprise Security Cloud app. The Splunk-supported app provides Talos lookup and adaptive response capabilities for Splunk Enterprise Security Cloud, including:

  • Intelligence Enrichment with Talos: Enriches an IP address, domain, or URL associated with a finding.
  • Intelligence Collection from Talos: Writes returned reputation data to a selected Splunk index from an event-based detection.

The Splunkbase app and the TIM Cloud Investigation enrichment are related Enterprise Security capabilities, but they are not the same workflow:

TIM Cloud Investigation enrichment Splunkbase Enterprise Security app
Runs through the TIM Cloud service. Runs as a Talos lookup or adaptive response action in Enterprise Security.
Requires TIM Cloud to be enabled. Requires the app to be installed on a supported Enterprise Security Cloud deployment.
Presents context on the investigation Intelligence tab. Adds enrichment to a finding or writes collected results to a selected index.
Supports IP address, domain, URL, and SHA-256 file hash at the service layer. The documented adaptive response actions support IP address, domain, and URL.
Does not populate ES Native. Collection results can be staged in an index, but they are not automatically added to ES Native.
Note:

Verify the current compatibility information listed in Splunkbase before installation.

The Splunkbase Talos apps are not supported for FedRAMP deployments. Confirm current compliance and regional availability before deployment.

Cisco Talos Intelligence connector for Splunk SOAR Cloud is a separate connector available in Splunkbase. The SOAR connector supports IP reputation, domain reputation, and URL reputation actions in playbooks. It is outside the TIM Cloud and ES Native workflows described in this topic.

Use Splunkbase collection results with ES Native

The Splunkbase collection action can write Talos results to a Splunk index. Writing those results to an index does not make them ES Native threat intelligence.

If your organization chooses to use the collected results with ES Native, you must create and maintain a separate ingestion design that does the following:

Note: This optional customization is not part of TIM Cloud Talos enrichment and is not created when you install the Splunkbase app.
  1. Maps the collected Talos observable and metadata fields to a supported ES Native threat intelligence type See Supported types of threat intelligence in Splunk Enterprise Security.
  2. Defines source, confidence, expiration, and deduplication behavior.
  3. Loads normalized records into the appropriate ES Native threat-intelligence collection by using a supported custom source or ingestion process.
  4. Enables and validates the applicable ES Native threat-matching searches.

Troubleshoot Talos enrichment

If Talos context does not appear in an investigation, check the following items:

  • Verify that TIM Cloud is enabled for the Enterprise Security environment. Talos Investigation enrichment is unavailable without TIM Cloud.
  • Verify that at least one TIM Cloud source is active and at least one threat list exists so that the Intelligence tab is available.
  • Confirm that the investigation contains a supported observable.
  • If many observables are present, retry with no more than 20 observables in a request.
  • If no Talos context appears for an observable, confirm that the value is valid and eligible for enrichment.
  • Confirm that the user has access to the investigation and the TIM Cloud intelligence service.
  • Distinguish errors in the built-in Investigation enrichment from errors in the separately installed Splunkbase adaptive response app.