Yeti platform

yeti-cli observables add <ioc>

Manage the Yeti threat intel platform with the CLI: add and query observables (IOCs) with automatic enrichment.

Run it when you want to manage Yeti from the command line: yeti-cli observables add registers the observable (the IOC: the domain, the IP, the hash) in the platform, which automatically enriches it (external sources: analyses, reputations) and relates it to indicators and entities. It's the intel platform with enrichment (from Yeti/Yeti-project): observables with automatic context. In the SOC and threat intel, Yeti is the observables platform: registered and enriched IOCs feed detections and cases.

Don't use it without the platform: yeti-cli requires the Yeti server and credentials — infrastructure is a prerequisite. And watch out: enrichment depends on configured sources (analyzers) — unconfigured sources leave the observable without context. Observables are curated (noise and false positives from public sources). For graph analysis, use the Yeti UI; the CLI is for programmatic operations.