View Investigation Additional Enrichment Data

If the selected indicator is an IOC (indicator of compromise), you can see additional Threat Command enrichment data in the following tabs (shown only if they are relevant):

  • Related File Hashes - Shows the file hashes related to the IOC.
  • WHOIS - Shows the WHOIS information.
  • CPEs - Shows information about the CPEs affected by the CVE.
  • Resolutions - Shows information for resolved IP addresss or domains.
  • DNS - Shows information about the DNS entries.
  • Subdomains - Shows additional subdomains.
  • Web Components - Show shte web components related to the IOC.

On most of these tabs, you can download the information to a CSV file with the Export all link.