Fortsatte roadmapen med multi-entity stream profiles
This commit is contained in:
@@ -40,7 +40,7 @@ Acceptance: each finding shows its detector, confidence, baseline sample count,
|
||||
|
||||
Goal: make one incident answer what happened, to whom, and across which sources.
|
||||
|
||||
- [ ] Allow multiple entity fields per stream, such as user plus source IP plus hostname.
|
||||
- [x] Allow multiple entity fields per stream, such as user plus source IP plus hostname.
|
||||
- [ ] Add entity aliasing: map DHCP, VPN, DNS, and endpoint identities to the same host where evidence supports it.
|
||||
- [ ] Add configurable incident grouping windows and incident lifecycle: open, acknowledged, resolved, reopened.
|
||||
- [ ] Persist incident state and analyst notes separately from transient detection output.
|
||||
|
||||
Reference in New Issue
Block a user