You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The field for an IP address to be stored in a network connection info object is unclear. The discussion identified the likely suspect of adding an IP address to the uid field which makes sense given the context. Some examples would be helpful
The text was updated successfully, but these errors were encountered:
I have a question regarding the Network Remediation Activity class. This class requires the connection_info attribute, which corresponds to the Network Connection Information object. However, this object seems to lack an attribute for storing an IP address
As a producer, when I detect a remote ransomware attack on my shared files, I isolate the remote endpoint and intend to generate a corresponding Network Remediation Activity event. Where within the object can I record the IP address of the remote endpoint? (edited)
Based on discussion at https://opencybersecu-lz97379.slack.com/archives/C03C2QPSBPB/p1727259577114689
The field for an IP address to be stored in a
network connection info
object is unclear. The discussion identified the likely suspect of adding an IP address to theuid
field which makes sense given the context. Some examples would be helpfulThe text was updated successfully, but these errors were encountered: