Fortsatte roadmapen med multi-entity stream profiles

This commit is contained in:
larssand
2026-06-29 19:08:23 +02:00
parent 20b0e0a92e
commit 68370217da
10 changed files with 102 additions and 60 deletions

View File

@@ -40,7 +40,7 @@ Acceptance: each finding shows its detector, confidence, baseline sample count,
Goal: make one incident answer what happened, to whom, and across which sources.
- [ ] Allow multiple entity fields per stream, such as user plus source IP plus hostname.
- [x] Allow multiple entity fields per stream, such as user plus source IP plus hostname.
- [ ] Add entity aliasing: map DHCP, VPN, DNS, and endpoint identities to the same host where evidence supports it.
- [ ] Add configurable incident grouping windows and incident lifecycle: open, acknowledged, resolved, reopened.
- [ ] Persist incident state and analyst notes separately from transient detection output.