-
Notifications
You must be signed in to change notification settings - Fork 162
Updates attack-discovery.md
#453
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
|
||
For a demo, refer to the following video. | ||
|
||
<!-- ::::{admonition} |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The current syntax guide doesn't contain guidance for videos. Florent seemed to have figured out a workaround (see this Slack thread) that we might be able to use if needed.
There are several ways you can incorporate discoveries into your {{elastic-sec}} workflows: | ||
|
||
* Click an entity’s name to open the user or host details flyout and view more details that may be relevant to your investigation. | ||
* Hover over an entity’s name to either add the entity to Timeline () or copy its field name and value to the clipboard (). |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Resizes the icons and makes them smaller
* Hover over an entity’s name to either add the entity to Timeline () or copy its field name and value to the clipboard (). | |
* Hover over an entity’s name to either add the entity to Timeline () or copy its field name and value to the clipboard (). |
* [How to generate discoveries](#attack-discovery-generate-discoveries) | ||
* [What information each discovery includes](#attack-discovery-what-info) | ||
* [How you can interact with discoveries to enhance {{elastic-sec}} workflows](#attack-discovery-workflows) |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
These anchor links aren't working properly in the preview, but since the syntax looks correct and the build is passing, it probably shouldn't be a blocker for merging.
Colleen's PR from her script has a more recent version; so closing this one. |
For migration cleanup. Check on syntax for embedded videos.