You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Enrichments is needed in Evidence Artifact's objects in Detection findings.
We can add the same Enrichments Array as we have on Detection finding level, but we can include it inside OCSF Object (Evidence Artifact's object) level.
Why it's important?
Not all attributes can be mapped directly in Evidence object, there could be some additional attributes, that's relevant for specific objects (like user-agent in src_endpoint(Network Endpoint object) for web-communication).
During addtional investigation when you need to add additional enrichments for this Evidence objects' attributes, you don't have place to do it by now.
Detection Finding's Enrichment's array can't be used for that because it doesn't have 'link' to exact object in Evidence Artifacts.
For example you want to put 'user-agent' there, but you can't clearly indicate if it's for src_endpoint or dst_endpoint
The text was updated successfully, but these errors were encountered:
Add
Enrichments Array
on an OCSF object's level.Enrichments is needed in Evidence Artifact's objects in
Detection findings
.We can add the same
Enrichments Array
as we have onDetection finding
level, but we can include it inside OCSF Object (Evidence Artifact's object) level.Why it's important?
Evidence
object, there could be some additional attributes, that's relevant for specific objects (likeuser-agent
insrc_endpoint
(Network Endpoint object) for web-communication).Detection Finding's
Enrichment's array
can't be used for that because it doesn't have 'link' to exact object inEvidence Artifacts
.For example you want to put '
user-agent
' there, but you can't clearly indicate if it's forsrc_endpoint
ordst_endpoint
The text was updated successfully, but these errors were encountered: