You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: solutions/security/investigate/indicators-of-compromise.md
+13-15Lines changed: 13 additions & 15 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -15,8 +15,6 @@ The Indicators page collects data from enabled threat intelligence feeds and pro
15
15
16
16
***{{agent}}** - Install a [{{fleet}}-managed {{agent}}](https://www.elastic.co/guide/en/fleet/current/install-fleet-managed-elastic-agent.html) and ensure the agent’s status is `Healthy`. Refer to [{{fleet}} Troubleshooting](../../../troubleshoot/ingest/fleet/common-problems.md) if it isn’t.
17
17
***{{filebeat}}** - Install [{{filebeat}}](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-installation-configuration.html) version 8.x or later. Earlier {{filebeat}} versions are incompatible with ECS and will prevent indicator data from displaying in the Indicators table.
18
-
19
-
20
18
::::
21
19
22
20
@@ -41,9 +39,9 @@ Install a threat intelligence integration to add indicators to the Indicators pa
41
39
2. In the search bar, search for `Threat Intelligence` to get a list of threat intelligence integrations.
42
40
3. Select a threat intelligence integration, then complete the integration’s guided installation.
43
41
44
-
::::{note}
45
-
For more information about available fields, go to the [Elastic integration documentation](https://docs.elastic.co/integrations) and search for a specific threat intelligence integration.
46
-
::::
42
+
::::{note}
43
+
For more information about available fields, go to the [Elastic integration documentation](https://docs.elastic.co/integrations) and search for a specific threat intelligence integration.
44
+
::::
47
45
48
46
4. Return to the Indicators page in {{elastic-sec}}. Refresh the page if indicator data isn’t displaying.
49
47
@@ -64,17 +62,17 @@ Learn more about an indicator by clicking **View details**, then opening the Ind
64
62
65
63
***Overview**: A summary of the indicator, including the indicator’s name, the threat intelligence feed it came from, the indicator type, and additional relevant data.
66
64
67
-
::::{note}
68
-
Some threat intelligence feeds provide [Traffic Light Protocol (TLP) markings](https://www.cisa.gov/tlp#:~:text=Introduction,shared%20with%20the%20appropriate%20audience). The `TLP Marking` and `Confidence` fields will be empty if the feed doesn’t provide that data.
69
-
::::
65
+
::::{note}
66
+
Some threat intelligence feeds provide [Traffic Light Protocol (TLP) markings](https://www.cisa.gov/tlp#:~:text=Introduction,shared%20with%20the%20appropriate%20audience). The `TLP Marking` and `Confidence` fields will be empty if the feed doesn’t provide that data.
@@ -137,9 +135,9 @@ When you attach an indicator to a case, the indicator is added as a new comment
137
135
138
136
***Overview**: A summary of the threat indicator, including its name and type, which threat intelligence feed it came from, and additional relevant data.
139
137
140
-
::::{note}
141
-
Some threat intelligence feeds provide [Traffic Light Protocol (TLP) markings](https://www.cisa.gov/tlp#:~:text=Introduction,shared%20with%20the%20appropriate%20audience). The `TLP Marking` and `Confidence` fields will be empty if the feed doesn’t provide that data.
142
-
::::
138
+
::::{note}
139
+
Some threat intelligence feeds provide [Traffic Light Protocol (TLP) markings](https://www.cisa.gov/tlp#:~:text=Introduction,shared%20with%20the%20appropriate%20audience). The `TLP Marking` and `Confidence` fields will be empty if the feed doesn’t provide that data.
0 commit comments