Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[FR] ThreatHunting Section #406

Open
YouBaxter opened this issue Feb 9, 2024 · 0 comments
Open

[FR] ThreatHunting Section #406

YouBaxter opened this issue Feb 9, 2024 · 0 comments
Labels
enhancement New feature or request

Comments

@YouBaxter
Copy link

Would be great to see a "ThreatHunting" Section added along with "Alerts" and "Cases".

The use case here would be to track internal threat hunts, and then, if needed, it can be escalated/migrated to a case (similar to an alert). In other words, if a defined threat hunt would lead to a true positive outcome the casing logic can be utilized (similar to an Alert>Case workflow).

Using the structure of the "Cases" module as a template, the Threat Hunting logic can be very similar with the only different would be to escalated to a incident/case or tagged as a false finding.

Thanks!!!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

1 participant