You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
@piaudonn I've been thinking about taking this on next. I think initially I'd be looking to modify the base module to normalize the mail message entity to ensure that we have these properties:
From there I think we have a few options to make that useful like:
Base module comment with basic message information and link to the email page where they could take action on the message
Threat Intel module update to look at the URLs/File hash data and cross reference Sentinel TI
We may need to see if we need to extract the Sender/Recipient and turn these into account entities as well, if the incidents don't consistently already do that, so that we could do analysis on the account in other STAT modules
Enrich mailmessage entities with the new analyzed message API
The text was updated successfully, but these errors were encountered: