Vectra threat intelligence

What is Vectra Threat Intel?
Who has access to Vectra Threat Intel?
Where does Vectra Threat Intel come from?
What functionality comes from Vectra Threat Intel?
Why do I see the same IOC on a host machine and my name server / domain controller?
Can I use my own threat intel with Vectra?
How should I investigate Vectra Threat Intel Match alert?
How are Vectra Threat Intel Match alerts scored?
What information is in the Attacker Details field?
How can I triage Vectra Threat Intel Match alerts?
Why do I see Vectra Threat Intel Match alerts with 0 bytes?
Why can I not find references to the attacker group being associated with the alerted indicator on the internet?
Can I disable Vectra Threat Intel?

Last updated
Was this helpful?