SOC
アラートエンリッチメント
The process of adding contextual information to security alerts, such as asset details, user context, or threat intelligence, to improve investigation and response efficiency.
Quick answer: The process of adding contextual information to security alerts, such as asset details, user context, or threat intelligence, to improve investigation and response efficiency.
This term page is part of the Protermify Cybersecurity glossary and is published as static HTML for fast indexing and clear language coverage.
Definition
The process of adding contextual information to security alerts, such as asset details, user context, or threat intelligence, to improve investigation and response efficiency.
Operational example
Alert enrichment correlates basic SIEM alerts with asset criticality and threat intelligence to reduce false positives and improve triage.
Localized term
アラートエンリッチメント
Localized example
アラートエンリッチメントは基本的なSIEMアラートを資産の重要度や脅威インテリジェンスと関連付け、誤検知を減らしトリアージを改善します。
Definition language
English reference definition
Source
ISO 27001, NIST Cybersecurity Framework, MITRE ATT&CK
Exam relevance
- CISSP
- CompTIA Security+
- CEH
Target audience
- SOC Analysts
- Security Engineers
- Incident Responders