You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Like for Responders, it could be useful to run operations with Analyzers.
Example of useful operations would be: AddArtifactToCase (this action is already supported for Responders. This could be useful for Analyzers to selects some observables that we are sure they should be added as new observables (ex: source email address of a malspam, URL of a malicious connexion reported by SIEM/proxies, download a VT sample from a hash report...)
The text was updated successfully, but these errors were encountered:
Very usefull indeed. However in some cases, it would be usefull to set on an analyzer configuration level, which type of artifact to add. From Virust Total report it might be usefull to add domains and IPs maybe. Hundreds of urls - also benign ones - not so much.
Like for Responders, it could be useful to run operations with Analyzers.
Example of useful operations would be: AddArtifactToCase (this action is already supported for Responders. This could be useful for Analyzers to selects some observables that we are sure they should be added as new observables (ex: source email address of a malspam, URL of a malicious connexion reported by SIEM/proxies, download a VT sample from a hash report...)
The text was updated successfully, but these errors were encountered: