IOC Enrichment, Blocking & Release
IOC Enrichment, Blocking & Release
A production module inside a Security Command Center (SCC) platform that aggregates indicators of compromise from many intelligence sources, deduplicates and enriches them into a single scored feed, manages their block / release lifecycle, and keeps the enterprise SIEM and firewalls automatically in sync, exposing the result as standards-based threat feeds.
// Background
Overlapping provider feeds, a hand-managed SIEM
blocklist, and no lifecycle, coverage always unknown.
Duplicated, inconsistent scoring
Same indicator from multiple providers with different
or missing scores; no unified, comparable view.
No single deduplicated source of truth
Manual SIEM updates won't scale
Hand-managing blocklists slow, error-prone, stale
orphans lingered after indicators were retired.
Stale entries outlived the threats they blocked
No managed lifecycle
Block/unblock decisions lived in side-channels; no
record of what was blocked, why, or when released.
Governance was an afterthought, not a workflow
Hard to integrate downstream
Other tools needed STIX/CSV/JSON; bespoke DB
not directly consumable without custom glue.
Every consumer needed a custom integration
Net effect
Analysts spent time managing lists instead of
investigating threats, with no audit trail.
// Solution
Data sources
Commercial threat intel
IOC: IPs · domains · hashes
daily parallel ingest
Open source intelligence
community feeds + bulk uploads
Pipeline
Ingest
Airflow
raw landing
Ingest
Enrich
dedup · score
last-seen
Enrich
Materialize
atomic swap
OLAP + archive
Fact
Lifecycle
block · release
Vue 3 · bulk
Govern
Distribute
SIEM · 15 min
STIX/TAXII · CSV · JSON
Distribute
Airflow · parallel multi-source ingest · dedup + risk scoring · atomic swap · block/release · 15-min SIEM sync
// Impact
SIEM: manual lists → auto sync
Before · by hand
slow · error-prone · stale orphansAfter · auto sync
adds new · prunes stale · 15 min15 min
SIEM sync cycle, always current
Operational impact
Deduplicated, risk-scored feed
noisy providers → one source of truth
Always-current SIEM defenses
15-min delta adds new, prunes stale
Governed block & release lifecycle
auditable workflows + bulk upload
Drop-in interoperability
STIX/TAXII · CSV · JSON feeds
Reliable, consistent dashboards
atomic swap: no partial reads
History stays lean
archive keeps recent N per indicator
Results
IOC types
4
SIEM sync cycle
~15 min
auditable
100%
Export formats
3+
Block/release tracked per indicator
keeps history lean over time.
| Layer | Technologies |
|---|---|
| Orchestration | Apache Airflow, daily TIP DAG (ingest → enrich → fact → archive) + 15-min SIEM-sync DAG, Papermill |
| Ingestion / enrichment | Multiple commercial & open threat-intel sources, Python requests, pandas, parallel tasks |
| Data store | PostgreSQL, raw landing, deduplicated summary, atomically-swapped OLAP fact table, archive tables, IOC dimension |
| Distribution | STIX/TAXII 2.1, CSV, JSON, plaintext feed endpoints; enterprise SIEM admin API (bearer auth, batched add/delete) |
| Backend API | FastAPI, in-memory CacheStore, psycopg / SQLAlchemy |
| Frontend | Vue 3, Quasar, Vite, TypeScript, Pinia, TanStack Vue Query, ECharts |
Indicators from several vendors are enriched and scored, then managed through a block and release lifecycle that feeds downstream security tools.
Disclaimer: sample visuals may contain anonymized, simulated, or non-production values for presentation purposes.