Open ruppde opened 1 year ago
Hi there! We don't have a concept in DFIQ for priority, which is why you can't sort questions by it.
I'd be interested in any thoughts around how a priority system in DFIQ would work.
My thoughts on the issue are:
DFIQ is trying to stay out of the "flowchart" part of making playbooks/runbooks; that feels too brittle and subjective and would need a lot of maintenance and room for discussions as to the "correct" way. Keeping DFIQ more focused on Questions allows it to focus more on facts (what files were downloaded? was psexec run?) rather than investigation philosophies on what to do when.
That was a long-winded response, but DFIQ is still in the early stages so we have a lot of this kind of "philosophical" stuff to hash out still - so thanks for the question! We definitely need to consider stuff like this.
The order doesn't have to be mandatory, but it probably would help to have the common stuff first, once you have bigger scenarios like e.g. creation of backdoors.
Priority is not only subjective also highly context specific, in a traditional Microsoft shop the standard Windows artifacts might be common, but in a cloud first organization unlikely. "common" is typically limited to your reference data set.
Also what do you want to use priority for? Detection? Triage? The term investigation implies a certain level of comprehensiveness.
Expected Behavior
Sort questions by priority
Actual Behavior
Questions sorted by ID
Specifications