IntegralDefense / ACE

Analysis Correlation Engine
Apache License 2.0
25 stars 10 forks source link

CarbonBlackProcessAnalysis Module tuning #171

Closed seanmcfeely closed 5 years ago

seanmcfeely commented 5 years ago

I don't like how verbose this module has become. It ends up adding too many process guids to alerts that can be distractions. I want to change this so that it's much more selective about the process guid's it adds to an analysis.