The CTI-in-SOC failure mode
Cyber threat intelligence programmes fail quietly. The feeds keep arriving, the dashboards keep populating, and nobody notices that the intelligence has stopped influencing decisions. Four problems compound to produce this outcome.
- Feed volume: tens of thousands of indicators arrive daily across commercial, open-source, and ISAC sources, far beyond what analysts can review individually.
- Freshness decay: a large share of published IOCs are stale by the time they reach the SIEM, matching infrastructure the adversary has already abandoned.
- Low per-indicator value: a single hash or IP address, without context on targeting, technique, or campaign, tells an analyst almost nothing actionable.
- No local relevance: feeds describe global adversary activity, not which of your assets, identities, or open cases the activity actually touches.
What AI-driven enrichment actually does
Enrichment is not indicator lookup. It is the set of automated steps that convert an anonymous, global signal into a statement about your specific environment. AI-driven enrichment does this at four levels.
- Semantic clustering of reports: natural language processing groups intelligence reports, advisories, and vendor writeups describing the same campaign, even when naming conventions differ.
- Actor and campaign correlation: indicators are linked back to known threat actors and campaigns using infrastructure overlap, tooling similarity, and historical attribution, not just static tags.
- TTP mapping to observed telemetry: adversary techniques described in a report are matched against detection logic and telemetry already running in the environment, so gaps are visible immediately.
- Freshness-weighted scoring: every indicator carries a decaying confidence score based on age, source reliability, and corroboration, so stale intelligence stops competing for analyst attention.
The enrichment pipeline
Enrichment has to be a pipeline, not a one-off transformation, because intelligence value changes as new corroborating data arrives. A practical pipeline has five stages.
- Ingest: pull from commercial feeds, OSINT, sector ISACs, and private or customer-specific sources into a common schema.
- Normalise: reconcile inconsistent naming, deduplicate overlapping reports, and standardise confidence and severity fields.
- Correlate: match indicators and TTPs against local telemetry, asset inventory, identity exposure, and open investigations.
- Score: apply freshness, source reliability, and local-relevance weighting to rank findings by operational impact rather than raw volume.
- Distribute: route high-scoring findings to the reasoning layer for action, and archive low-scoring ones without consuming analyst time.
Integration with the reasoning layer and investigation fabric
Enrichment only pays off if the output reaches the systems that act on it. Inside Sphere, enriched CTI feeds directly into SAGE, the reasoning layer that evaluates each finding against policy and case context before deciding whether it warrants autonomous action or human review.
Enriched findings that touch an active case are attached to that case inside AuraXP, the investigation fabric, rather than opened as a separate alert. An analyst working a suspected intrusion sees the relevant campaign attribution, TTP overlap, and confidence score inside the same investigation timeline, instead of cross-referencing a separate CTI portal.
From "block this hash" to "prioritise this narrative"
The operational shift enrichment enables is a change in the unit of decision. Feed-based CTI produces indicator-level actions: block a hash, add an IP to a watchlist, tag a domain. AI-driven enrichment produces narrative-level guidance: this campaign is actively targeting our sector, these three techniques map to gaps in our detection coverage, and these two open cases likely belong to the same actor.
Narrative-level output is what lets a SOC allocate scarce analyst time to the threats that matter, rather than processing every indicator with equal urgency.
Measuring enrichment quality
CTI programmes are rarely measured against outcomes, which is part of why they drift into feed accumulation. Two metrics separate enrichment that works from enrichment that only looks busy.
- Analyst-time-saved: hours no longer spent manually triaging indicators, correlating reports, or cross-checking asset exposure by hand.
- Decision-influence rate: the proportion of enriched findings that materially changed a SOC decision, whether that is opening a case, adjusting detection coverage, or closing a false lead faster.
- A programme that scores well on indicator throughput but poorly on decision-influence rate is optimising the wrong variable.
OT and regulated-industry considerations
Enrichment logic needs to account for environments where indicator-based blocking is not a safe default action. In OT and industrial settings, an enriched finding about a campaign targeting engineering workstations should trigger heightened monitoring and change-control review, not an automatic block that could disrupt a control loop.
Regulated sectors also need enrichment output that supports audit and reporting obligations: a defensible record of why a piece of intelligence was scored, correlated, and escalated the way it was, not just the final action taken.
How Spharaka delivers this
Spharaka's Cyber Threat Intelligence capability inside Sphere ingests multi-source feeds, runs the normalise, correlate, and score pipeline continuously, and hands enriched findings to SAGE and AuraXP as a live input rather than a static report. IOC enrichment, malware and vulnerability intelligence, and campaign attribution all flow into the same reasoning surface used by threat hunting, detection, and response.
The outcome is a CTI function that shapes decisions across the SOC in real time, with a track record analysts and compliance teams can both point to.
Frequently asked questions
Do we still need a dedicated CTI team?
Yes. Strategic intelligence, adversary tracking, and bespoke research still require human analysts. AI-driven enrichment removes the mechanical triage burden so the CTI team can spend its time on judgement calls that automation should not make alone.
How does AI-driven CTI reduce false positives?
By evaluating every indicator against local context before it becomes an alert. An indicator that matches nothing in the environment does not need to fire; one that matches an asset already covered by a running investigation is attached to that investigation instead of raised separately.
Which feed sources does Spharaka integrate?
Commercial feeds, open-source intelligence, sector ISAC feeds, and customer-specific private intelligence. The full integration list is a product conversation; contact the Spharaka team for the current inventory.
How is enrichment quality measured in practice?
Through analyst-time-saved and decision-influence rate: how much manual triage time is eliminated, and what proportion of enriched findings actually changed a SOC decision rather than sitting unread in a dashboard.
Is AI-driven enrichment safe for OT and industrial environments?
Yes, when enrichment logic is aware of the environment. Findings relevant to OT assets are routed to heightened monitoring and change-control review rather than automatic blocking actions that could affect a control process.


