Skip to content
Discussion options

You must be logged in to vote

Yes, this is basically the intended flow. All findings can be stateful, but whereas Vulnerability Finding, Compliance Finding, and Detection Finding are focused on their respective domains, Incident Finding combines one or more of any of them into something that is the ultimate conclusion with an overal set of scores, a verdict etc.

Because people were wanting the Incident Finding semantics and attributes without having to create another aggregating structure we added the Incident profile which can augment any of the Finding classes to include what Incident Finding has.

Detection Finding has related events, as in your picture above, with some Analytic behind the finding. Incident Finding …

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@Haribu
Comment options

Answer selected by Haribu
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants