#2:
Improved Investigations through Contextual Link Analysis
Once an event has been escalated, D3 automatically correlates IOCs—such as source IP/domain, destination IP/domain, file hashes, etc.— and MITRE ATT&CK techniques against threat intelligence, historical incident data, and potential traces of a larger kill chain, painting a complete picture of the threat. An intuitive link analysis dashboard provides analysts with the dexterity and visualizations needed for complex investigations. Adding D3’s link analysis to ArcSight ESM events provides users with vastly improved triage, the ability to easily spot false positives, and better handling of complex incidents. By bringing the information needed for investigations into a single platform, organizations can reduce SOC fatigue by eliminating context-switching, while improving response through integrated intelligence.