google / dfiq

DFIQ is a collection of investigative questions and the approaches for answering them
http://dfiq.org/
Apache License 2.0
262 stars 21 forks source link

Feature idea #3

Open ruppde opened 1 year ago

ruppde commented 1 year ago

Expected Behavior

Sort questions by priority

Actual Behavior

Questions sorted by ID

Specifications

obsidianforensics commented 1 year ago

Hi there! We don't have a concept in DFIQ for priority, which is why you can't sort questions by it.

I'd be interested in any thoughts around how a priority system in DFIQ would work.

My thoughts on the issue are:

ruppde commented 1 year ago

The order doesn't have to be mandatory, but it probably would help to have the common stuff first, once you have bigger scenarios like e.g. creation of backdoors.

joachimmetz commented 1 year ago

Priority is not only subjective also highly context specific, in a traditional Microsoft shop the standard Windows artifacts might be common, but in a cloud first organization unlikely. "common" is typically limited to your reference data set.

Also what do you want to use priority for? Detection? Triage? The term investigation implies a certain level of comprehensiveness.