Anomali Enterprise is responsible for search of signs of existence of indicators of a compromise (Indicator of Compromise/IOC) in a data stream in real time (Threat Hunting).
The product keeps record of the events happening in network with a depth of archive to 5 years and provides automatic search of IOC indicators in all depth of archive for shares of seconds.
Can act as initial data a log of monitoring systems of SIEM which can automatically be imported to Anomali Enterprise.