Overnight, a feed arrives with IPs, domains, and hashes matching last night's parking-meter malware. What is the right use of that intelligence in Splunk Enterprise Security?
Select an answer to reveal the explanation.
Short Explanation
Hashes and bad domains are license-plate numbers, not a state-of-the-city speech. Stuff them into ES threat lists so Web, DNS, and malware lookups can fire — do not walk them into council chambers. Strategic briefings need trends, not last night's meter hashes.
Full Explanation
Technical (indicator-level) intelligence is for matching and blocking: IPs, domains, and hashes loaded into the Enterprise Security threat-intelligence framework. A council briefing on nation-state targeting is strategic work and is not answered by last night's parking-meter IoCs. Architecture rewrites and "strategic because the asset is civic" both mis-tier the feed. Civic analysts should operationalize the indicators in lookups and correlation, then escalate only confirmed hits.