Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[DOCS] Threat Intelligence - Indicators Page and Indicator Details #2497

Closed
2 tasks
dhru42 opened this issue Sep 23, 2022 · 3 comments · Fixed by #2526
Closed
2 tasks

[DOCS] Threat Intelligence - Indicators Page and Indicator Details #2497

dhru42 opened this issue Sep 23, 2022 · 3 comments · Fixed by #2526

Comments

@dhru42
Copy link
Collaborator

dhru42 commented Sep 23, 2022

Description

With the work done over the last few release cycles:

  • users can now find all indicators from activated threat intelligence integrations/data sources in the Intelligence left-hand navigation. Once the user clicks on the Intelligence left-hand nav, they can see a centralized view of all IoCs reported from their TI feeds which allows for filtering, sorting, searching, adding to timeline, and more. (Epic)
  • From the Indicators page, the user can click on any Indicator and view more Details on the Indicator Details (flyout). The Indicator details flyout displays an overview tab, table tab, and JSON tab which the user can switch through to get more insight about the IoC. (Epic)
  • From either the main indicators page or Indicator details flyout, the user can also click on Investigate in Timeline button which adds the threat index value (threat.indicator.file.hash.sha256 = "c207213257a63589b1e1bd2f459b47becd000c1af8ea7983dd9541aff145c3ba") along with the associated value in the source index (file.hash.sha256 = "c207213257a63589b1e1bd2f459b47becd000c1af8ea7983dd9541aff145c3ba") into a new timeline. The goal with this functionality is so the user can easily find any matched activity within their environment, along with any alerts and other events that may have triggered. (Epic)

Definitions

What is Threat Intelligence?
Threat Intelligence is a research function that sits within the security operation center who is responsible for understanding current and emerging threats and recommending actions against these threats to protect their organizations.

What are IoCs?
An Indicator of Compromise - or IoC in short - is a document, a piece of information, that represents a known malicious threat or reported vulnerability. There are different types of IoCs, for example, URL, file, domain, email address, etc…

Acceptance Test Criteria

  • Please create public-facing documentation for elastic security users
  • Please add this to the new functionality in the 8.5 release notes

Notes

  • This functionality is only available for Enterprise license tier
@dhru42 dhru42 changed the title [DOCS] Threat Intelligence - Indicators Page and Indicator Details [Draft] [DOCS] Threat Intelligence - Indicators Page and Indicator Details Sep 23, 2022
@maxcold
Copy link
Contributor

maxcold commented Sep 27, 2022

here is the list of PRs related to the work described in the description. The PRs span between 8.4 and 8.5 as in 8.4 the features were under the feature flag but there was no mention of them in the release notes. In parenthesis my comments to extend on the PR title, happy to elaborate more if needed. Now the question is what is the good way to tag the PRs for the best representation in the release notes, especially when it comes to feature vs enhancement tagging

@maxcold
Copy link
Contributor

maxcold commented Sep 28, 2022

btw as far as I understand the PRs that we merged in 8.4 won't be picked up by the automation for 8.5 release notes. How do we go about it?

@maxcold
Copy link
Contributor

maxcold commented Sep 28, 2022

I tagged all the 8.5 PRs with Team:SecuritySolution and with a proper release_note label. But we also need feature release notes for the new Intelligence feature itself, which we introduced in 8.4 but behind a feature flag without any release notes. Maybe it makes sense to use this PR elastic/kibana#141117 where we remove the feature flag and going GA for the main "new Intelligence page" feature release note. I marked it accordingly.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging a pull request may close this issue.

5 participants