Enriching Data with Deloitte Codex
The Deloitte Codex enrichment gives you context on APT names from multiple vendors associated with malware, easy to understand malware naming, typing, execution information, and more. Enrichment information is displayed in the Enrichments section of observable details pages for domain, IP, email, hash and URL observables.
View documentation on the Deloitte Codex enrichment for Anomali
To activate the Deloitte Codex enrichment:
-
Navigate to ThreatStream > APP STORE > APP Store.
-
Locate the Deloitte Codex enrichment.
- Click Get Access on the Deloitte Codex tile.
- Click I have credentials.
-
On the next wizard page that opens, click Credentials and then enter your Deloitte Codex username and password.
-
Specify a Query Limit to limit the number of records returned when querying Deloitte. The default is 25. Specifying a query limit of 0 implies no limit.
- Click Activate.
The Deloitte Codex enrichment is now active.