@ekost,
My correlation search is generating all the fields required (i.e. I could add them to the title/description as variables), however I would like them to appear under "Additional Fields", where there is currently items such as:
Destination
Destination Expected
Destination Requires AntiVirus
Process
User
Obviously these are fields that are referenced in the CIM; I would like to add ones, e.g:
IOC Source
IOC Description
IOC Classification
IOC Date
Etc,
The intention is that I we can add these fields to the notables/events in Incident Review, so that the review is more streamlined and also so that we can create workflow actions on the IOC themselves (e.g. Open Source checks, checks on other systems internally, etc.) for each instance.
We do have other use cases, not just IOC information.
Hope this is a bit clearer.
Thanks,
Matt
... View more