-
Notifications
You must be signed in to change notification settings - Fork 634
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Display short reports on the Observables tab #131
Comments
This is something we have identified for quite some time and is on our roadmap for Q2/Q3. We are going to freshen the UI with 2.12.0 and the new UI will display that info. |
We are also very keen to see this feature introduced to enable quicker identification of relevant/malicious observables. Ideally all the short-report tags should be shown as part of the observable table. |
This feature will have a dependency on Cortex-Analyzers 1.5.0 release |
Request Type
Feature Request
Work Environment
Problem Description
The Observables tab is not currently very useful as it doesn't show short reports resulting from executed analyzers that would allow analysts to quickly weed through a large number of observables and/or aid their decision-making process.
Possible Solutions
Whenever a analyzer that supports short reports is executed such as VT or MaxMind, display the resulting short reports in the Observables page next to the observable.
Add the ability to filter against the short reports. For example, the analyst should be able to isolate all observables located in a particular country and apply complementary analysis etc.
The text was updated successfully, but these errors were encountered: