IntegralDefense / ACE

Analysis Correlation Engine
Apache License 2.0
25 stars 10 forks source link

Use ELK to get additional recipients of a message_id #209

Closed KarmaPenny closed 5 years ago

KarmaPenny commented 5 years ago

its possible for an alert to come in that was bcc'd or sent to other users but have no alert for those additional emails.

We should be able to query ELK for the message_id and locate any additional recipients. Then we can add those recipients to the alert. Along with remediation targets so all the emails get remediated.

KarmaPenny commented 5 years ago

used the email archive instead