VITI Security

Fable 5 for Security Teams: Enriching Indicators of Compromise

by VITI Security TeamJun 24, 2026

Fable 5 can cut the time analysts spend enriching indicators of compromise by handling the repetitive lookup and summarisation work - while keeping a human in the decision seat.

Fable 5 for Security Teams: Enriching Indicators of Compromise - VITI Security

Fable 5 for security teams is most useful when analysts are buried in raw indicators - IP addresses, file hashes, domains - and need context fast. By feeding Fable 5 a structured enrichment prompt, a junior analyst can surface reputation data, WHOIS history, malware family associations, and suggested triage priority in minutes instead of hours. A human still reviews and acts on every finding.

How to enrich indicators of compromise with Fable 5

01

1 - Collect your raw indicators

Export the indicators from your SIEM, EDR, or email gateway. Group them by type: IP addresses, domains, file hashes (MD5/SHA-256), and URLs. Keep each type in its own list. A clean input means a clean output - remove duplicates and strip any internal hostnames or private IP ranges before you paste anything.

02

2 - Pull external reputation data

Run each indicator through your chosen sources - VirusTotal for hashes and URLs, AbuseIPDB for IPs, WHOIS for domains. Copy the raw JSON or text output. You do not need to interpret it yet; you are gathering the raw material that Fable 5 will process in the next step.

03

3 - Feed Fable 5 a structured enrichment prompt

Paste your indicators and the raw lookup results into Fable 5 with a prompt such as: 'You are a threat intelligence analyst. For each indicator below, summarise: known malware associations, first seen / last seen dates, detection ratio, and recommended triage priority (high / medium / low / benign). Flag any gaps where data is missing.' Fable 5 reads across all the lookup outputs at once and produces a structured summary table - a task that would take a human analyst 20-40 minutes per batch.

04

4 - Review, verify, and act

A human analyst reads every row Fable 5 produces before any indicator is blocked, escalated, or closed. Spot-check three to five entries against the raw source data to confirm accuracy. Adjust any priority ratings that do not match your environment context - Fable 5 does not know your asset criticality. Once verified, push the enriched indicators into your SIEM or ticketing system with the analyst's name and review timestamp attached.

A worked example - using Fable 5 for security teams on a phishing campaign

A managed SOC analyst received 14 suspicious email headers from a client's Microsoft 365 tenant. The headers contained 6 sending IPs, 3 domains, and 2 attachment hashes. The analyst ran each through AbuseIPDB and VirusTotal (under 5 minutes using API calls), then pasted all output into Fable 5 with the enrichment prompt above. Fable 5 returned a summary table in under 2 minutes: 4 IPs flagged as high confidence malicious (linked to Emotet infrastructure), 1 domain registered 3 days prior with a privacy WHOIS, and 2 hashes matching a known QakBot dropper. The analyst confirmed three entries against the raw VirusTotal reports, escalated the client ticket to P1, and blocked all 6 IPs at the perimeter firewall within 18 minutes of the initial alert - a task that previously took close to an hour.

FAQ - Fable 5 for security teams and IoC enrichment

FAQ - Fable 5 for security teams and IoC enrichment

Can Fable 5 query VirusTotal or AbuseIPDB directly?
Not in its standard deployment. Fable 5 works with data you paste or import - it does not make live API calls on your behalf. Some enterprise integrations or plugin setups may change this, but the default workflow is: you pull the data, Fable 5 processes it. This also means you control exactly what leaves your environment.
Is this suitable for a small IT team without a dedicated SOC?
Yes - in fact that is where it adds the most value. A generalist IT admin handling security alerts can use Fable 5 to get analyst-level context on an indicator without needing deep threat intelligence experience. The caveat is the same: review the output, do not act on it blindly. If you are managing security for a business without in-house expertise, a managed security provider can own the review step for you.

Need faster threat triage without hiring a full SOC?

VITI Security provides managed detection and response for SMBs in India and the US - including indicator enrichment workflows built into your existing tools. Talk to us about what a practical, right-sized security operation looks like for your business.