-
Notifications
You must be signed in to change notification settings - Fork 206
Closed
Description
For the 8.5 Release, we will release Terminal Output Review for Session View
https://github.com/elastic/security-team/issues/2644
[after reading the ticket]
Description
This new feature will allow security analysts to view the terminal output in the session viewer to understand a compromised session better.
The ticket mentioned above has screenshots and video recordings of how navigation works and the information displayed.
What's needed
- Outline the business benefit from infosec analyst
- Outline how to enable output within settings; current Terminal Output has a default = off
- Outlined the workflow between session view jumping in and out of the terminal view
- Outline the controls within the terminal view
- Outline the index where to expect terminal output data streams