Azure / Azure-Sentinel

Cloud-native SIEM for intelligent security analytics for your entire enterprise.
https://azure.microsoft.com/en-us/services/azure-sentinel/
MIT License
4.37k stars 2.89k forks source link

Add Entity to existing Incident #10728

Open FormindGMO opened 2 days ago

FormindGMO commented 2 days ago

Is your feature request related to a problem? Please describe. When investigating an incident, we can find new items related to incident that can be useful to analyse.respond to/pivot against when new incidents will occur.

Describe the solution you'd like

Describe alternatives you've considered Workaround :

Additional context None.

v-sudkharat commented 1 day ago

Hi @FormindGMO, Thanks for flagging this issue, we will investigate this issue and get back to you with some updates by 12-07-2024. Thanks!

v-sudkharat commented 23 hours ago

Hey @FormindGMO, Could you please provide more details about the issue your facing, it would be great if you could attach screenshots as well. It helps us to investigate on it. Thanks!

FormindGMO commented 21 hours ago

Hello! thanks for fast reply. It's not an issue but rather a feature request. Let's illustrate w/ an example. Assuming an incident of a computer having a malware that was run on it. In this incident we can assume that we had FileHash entity pre-positioned, and targeted host.

Analyzing targeted host, we can see that malware reached Command&Control 1.2.3.4. I want to :

So my feature could be to manually (or via Logic Apps) add entity to Incidents.