You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
When we make a judgement, we should be able to specify and :action that is suggested to take when the observable in the judgement is seen. The possible values are pulled from the OpenC2 spec, DENY, ALLOW, ALERT with a default of DENY. This will allow us to use the CTIM to capture "watchlists".
Some side-effects of this:
When we import Indicators and they reference COAs, do we have to now extract the suggested COA?
Do we need an API call to change the action of a judgement?
Should the action be ignored if there is an Indicator?
The text was updated successfully, but these errors were encountered:
I am not so sure we want to have this double coding, so moving off debutant. It's not that hard for us to provide a default indicator and COA for block and allow.
When we make a judgement, we should be able to specify and
:action
that is suggested to take when the observable in the judgement is seen. The possible values are pulled from the OpenC2 spec, DENY, ALLOW, ALERT with a default of DENY. This will allow us to use the CTIM to capture "watchlists".Some side-effects of this:
The text was updated successfully, but these errors were encountered: