socfortress / CoPilot

SOCFortress CoPilot
https://www.socfortress.co
GNU Affero General Public License v3.0
193 stars 40 forks source link

DFIR-IRIS Alert/Case Counts and Enrichment triggers #174

Closed chadhardcastle closed 3 weeks ago

chadhardcastle commented 6 months ago

Hey there,

Feature Requests:

Possible Bug: On a separate note I noticed that the ascending vs. descending filter doesn't seem to update anything when doing a search of the alerts. This could potentially be due to the fact I have almost 15000 alerts as part of my testing. I increased the CPU and memory resources to ensure it wasn't a bottleneck in my cluster.

Thanks again, great product so far!

taylorwalton commented 3 weeks ago

no longer leveraging dfir-iris