Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Display short reports on the Observables tab #131

Closed
saadkadhi opened this issue Feb 22, 2017 · 3 comments
Closed

Display short reports on the Observables tab #131

saadkadhi opened this issue Feb 22, 2017 · 3 comments
Assignees
Milestone

Comments

@saadkadhi
Copy link
Contributor

Request Type

Feature Request

Work Environment

Question Answer
OS version (server) Ubuntu
OS version (client) Ubuntu
TheHive version / git hash 2.10.0
Package Type Binary

Problem Description

The Observables tab is not currently very useful as it doesn't show short reports resulting from executed analyzers that would allow analysts to quickly weed through a large number of observables and/or aid their decision-making process.

Possible Solutions

Whenever a analyzer that supports short reports is executed such as VT or MaxMind, display the resulting short reports in the Observables page next to the observable.

Add the ability to filter against the short reports. For example, the analyst should be able to isolate all observables located in a particular country and apply complementary analysis etc.

@saadkadhi
Copy link
Contributor Author

This is something we have identified for quite some time and is on our roadmap for Q2/Q3. We are going to freshen the UI with 2.12.0 and the new UI will display that info.

@bullerdude
Copy link

We are also very keen to see this feature introduced to enable quicker identification of relevant/malicious observables. Ideally all the short-report tags should be shown as part of the observable table.

@nadouani
Copy link
Contributor

nadouani commented Jun 20, 2017

This feature will have a dependency on Cortex-Analyzers 1.5.0 release

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

4 participants