-
Notifications
You must be signed in to change notification settings - Fork 0
Add custom lookup enrichment tables #33
Copy link
Copy link
Open
Labels
area:enrichmentContext enrichment and lookup dataContext enrichment and lookup dataarea:riskRisk scoring and risk contextRisk scoring and risk contextarea:threat-intelThreat intelligence indicators and feedsThreat intelligence indicators and feedspriority:mediumMedium priority implementation workMedium priority implementation work
Description
Metadata
Metadata
Assignees
Labels
area:enrichmentContext enrichment and lookup dataContext enrichment and lookup dataarea:riskRisk scoring and risk contextRisk scoring and risk contextarea:threat-intelThreat intelligence indicators and feedsThreat intelligence indicators and feedspriority:mediumMedium priority implementation workMedium priority implementation work
Problem
Threat intel enrichment is useful, but many investigation decisions depend on local context: asset criticality, user role, cloud account ownership, known service accounts, vulnerability exposure, and network zone.
Scope
Add tenant-scoped lookup tables that can enrich events, alerts, signals, and cases with local business/security context.
Implementation Notes
Acceptance Criteria
Tests