-
Notifications
You must be signed in to change notification settings - Fork 8.5k
Closed
Task
Copy link
Labels
Team: SecuritySolutionSecurity Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.Team:Threat HuntingSecurity Solution Threat Hunting TeamSecurity Solution Threat Hunting TeamTeam:Threat Hunting:InvestigationsSecurity Solution Threat Hunting Investigations TeamSecurity Solution Threat Hunting Investigations Team
Milestone
Description
Summary
We need to add a new field on the alert document to be able to store attack ids.
See this internal RFC
Acceptance criteria
- should have a field available for us to know which attack(s) an alert belongs to
Questions
- Are we sure this is the direction we want to take?
- What should we name this new field?
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
Team: SecuritySolutionSecurity Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.Team:Threat HuntingSecurity Solution Threat Hunting TeamSecurity Solution Threat Hunting TeamTeam:Threat Hunting:InvestigationsSecurity Solution Threat Hunting Investigations TeamSecurity Solution Threat Hunting Investigations Team
Type
Fields
Give feedbackNo fields configured for Task.