4.2 Data Processing: Prepare

Updated 2 years ago by TruSTAR

After an event is collected, the Intelligence Pipeline uses machine learning (ML) to automatically parse the information and extract more than a dozen types of Observables for further processing. 

The Pipeline automatically cleans up the data to make these Observables comparable across all of your intelligence sources.

Three specific types of cleanup are performed:

Lowercase Conversion: All Observables are converted to lowercase to increase the accuracy of correlating them across Reports and Enclaves. 

Defanging: Text is added to the Observable so that it does not appear as a live link in any reports. For example, the URL acmelimited.com would be modified to display as acmelimited[.]com.

Disambiguation: The Pipeline uses context to determine if the Observable is properly categorized..

How Did We Do?