Description
Request Type
Feature Request
Work Environment
TheHive v2.11.2
Description
-
In Alert Preview Artifacts doesn't show is there is "case" related, will be very interesting to avoid import "event into new case" if Analyst can obtain information about "artifacts" before import it.
-
When Analyst Import Alert and create "new case base on" in Observables Page list table, doesn't show "description info" about it, Analyst must to "entry" in each observable individually to see "related case" and know more about previous works.
Will be a great feature include a "brief" ,or even a box check where analyst can mark is observable should be reviewed or not.
Example: One type IP artifact seems be "clean", and traffic repeat frecuencly every day. If Analyst had not to entry in each one observable to know if other Analyst mark as clear with remember to "review" later (schedule)
- Remember me ! I would like a "remember me" or "follow-up" case options, this is important for us, sometime in incident is necesary to work with other team (system, red tem, others certs) and while waiting response, the incident / alerts keep on not wait for us ... the options follow-up or remeber, help to analyst dont forget case and working on later.
Brief
-
Add related case with artifacts in Alert preview.
-
Add schedule options to case , task or even observable (artifacts) to be reviewed later.
Thanks in advance
!great work!