You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
An example would be indexing indicators from a Phishing URL feed. If the indicator from the threat intelligence feed has the brand name set as a tag, we would set that tag to the elastic document.
Tags tend to be very generic so they can contain any keyword value, making it difficult to parse tags to a specific ECS field.
We noticed there's no ECS field for tags in the threat object.
I'd recommend threat.indicator.tags or threat.indicator.tag
The text was updated successfully, but these errors were encountered:
Many threat intelligence platforms use a tagging system to group indicators.
https://knowledge.threatconnect.com/docs/applying-tags
An example would be indexing indicators from a Phishing URL feed. If the indicator from the threat intelligence feed has the brand name set as a tag, we would set that tag to the elastic document.
Tags tend to be very generic so they can contain any keyword value, making it difficult to parse tags to a specific ECS field.
We noticed there's no ECS field for tags in the threat object.
I'd recommend threat.indicator.tags or threat.indicator.tag
The text was updated successfully, but these errors were encountered: