Threat Intelligence Platform (TIP)
Definition
A system that ingests indicator feeds from external providers and internal sources, deduplicates and scores them, and exports curated indicators of compromise to the SIEM and other tools for alert enrichment.
- Function
- Ingest, deduplicate, and score indicator feeds
- Inputs
- External providers and internal sources
- Output
- Curated indicators sent to the SIEM
- Purpose
- Alert enrichment
Common questions
What problem does a TIP solve that raw feeds alone do not?+
Raw feeds from multiple providers overlap heavily and vary in reliability, so a TIP deduplicates and scores indicators before they reach the SIEM, reducing alert noise from low-confidence or redundant data.
How does a TIP improve incident triage?+
By enriching alerts with context, such as which threat actor an indicator is associated with, analysts can prioritise investigating alerts tied to known active campaigns over isolated low-confidence hits.
Related terms
- EDR (Endpoint Detection and Response)
- An agent-based security tool deployed on individual endpoints (workstations, servers, mobile devices) that monitors process execution, file changes, network connections, and registry...
- MTTD / MTTR
- Mean Time to Detect and Mean Time to Respond: the two primary operational KPIs for a SOC. MTTD measures the gap between...
- SIEM (Security Information and Event Management)
- A platform that aggregates log and event data from systems, networks, and applications across an environment, correlates events against detection rules, generates...
- SOAR (Security Orchestration, Automation, and Response)
- A platform that receives alerts from the SIEM and other sources, executes automated playbooks to enrich and triage them, and integrates with...
- STIX / TAXII
- Structured Threat Information eXpression (STIX) is a standardised language for describing threat intelligence objects. Trusted Automated eXchange of Intelligence Information (TAXII) is...