v0.9.7
The target subdomain was only visible inside the detail modal. Add a Host column (after Source IP) showing the distinct vhosts/domains from the incident's evidence as amber chips (first 2 + a +N overflow), linking to the IP timeline. Shows a dash for incidents without a host (file-scan/SSH, or agents/setups where the host isn't captured).