You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Detection Finding's Evidence Artifacts represent collection of Evidences associated to the activity, that's why it should contain all possible objects that can be a part of detections or activity.
Now this list contains only this objects:
api
actor
connection_info
query
dst_endpoint
file
process
src_endpoint
We have additional objects that can be added to this list:
account
device
email
url
user
I'd suggest also to move Cloud and Resources to be a part of Evidence Artifact's as well, to make it with straight logic.
The text was updated successfully, but these errors were encountered:
Detection Finding
'sEvidence Artifacts
represent collection of Evidences associated to the activity, that's why it should contain all possible objects that can be a part of detections or activity.Now this list contains only this objects:
We have additional objects that can be added to this list:
I'd suggest also to move
Cloud
andResources
to be a part ofEvidence Artifact
's as well, to make it with straight logic.The text was updated successfully, but these errors were encountered: