Observables are the building blocks of security investigations. When an alert fires, analysts extract its associated observables and enrich them with context from threat intelligence sources, asset databases, and historical logs. The ability to quickly and accurately assess observables, determining whether they are known-malicious, suspicious, or benign, is foundational to effective triage and investigation.