Fable 5 for security teams is most useful when analysts are buried in raw indicators - IP addresses, file hashes, domains - and need context fast. By feeding Fable 5 a structured enrichment prompt, a junior analyst can surface reputation data, WHOIS history, malware family associations, and suggested triage priority in minutes instead of hours. A human still reviews and acts on every finding.
How to enrich indicators of compromise with Fable 5
1 - Collect your raw indicators
Export the indicators from your SIEM, EDR, or email gateway. Group them by type: IP addresses, domains, file hashes (MD5/SHA-256), and URLs. Keep each type in its own list. A clean input means a clean output - remove duplicates and strip any internal hostnames or private IP ranges before you paste anything.
2 - Pull external reputation data
Run each indicator through your chosen sources - VirusTotal for hashes and URLs, AbuseIPDB for IPs, WHOIS for domains. Copy the raw JSON or text output. You do not need to interpret it yet; you are gathering the raw material that Fable 5 will process in the next step.
3 - Feed Fable 5 a structured enrichment prompt
Paste your indicators and the raw lookup results into Fable 5 with a prompt such as: 'You are a threat intelligence analyst. For each indicator below, summarise: known malware associations, first seen / last seen dates, detection ratio, and recommended triage priority (high / medium / low / benign). Flag any gaps where data is missing.' Fable 5 reads across all the lookup outputs at once and produces a structured summary table - a task that would take a human analyst 20-40 minutes per batch.
4 - Review, verify, and act
A human analyst reads every row Fable 5 produces before any indicator is blocked, escalated, or closed. Spot-check three to five entries against the raw source data to confirm accuracy. Adjust any priority ratings that do not match your environment context - Fable 5 does not know your asset criticality. Once verified, push the enriched indicators into your SIEM or ticketing system with the analyst's name and review timestamp attached.
A worked example - using Fable 5 for security teams on a phishing campaign
A managed SOC analyst received 14 suspicious email headers from a client's Microsoft 365 tenant. The headers contained 6 sending IPs, 3 domains, and 2 attachment hashes. The analyst ran each through AbuseIPDB and VirusTotal (under 5 minutes using API calls), then pasted all output into Fable 5 with the enrichment prompt above. Fable 5 returned a summary table in under 2 minutes: 4 IPs flagged as high confidence malicious (linked to Emotet infrastructure), 1 domain registered 3 days prior with a privacy WHOIS, and 2 hashes matching a known QakBot dropper. The analyst confirmed three entries against the raw VirusTotal reports, escalated the client ticket to P1, and blocked all 6 IPs at the perimeter firewall within 18 minutes of the initial alert - a task that previously took close to an hour.
FAQ - Fable 5 for security teams and IoC enrichment
FAQ - Fable 5 for security teams and IoC enrichment
Can Fable 5 query VirusTotal or AbuseIPDB directly?
Is this suitable for a small IT team without a dedicated SOC?
Need faster threat triage without hiring a full SOC?
VITI Security provides managed detection and response for SMBs in India and the US - including indicator enrichment workflows built into your existing tools. Talk to us about what a practical, right-sized security operation looks like for your business.

