Inference rule: Indicator to Threat Correlation (through Infrastructure) #9596
Labels
feature
use for describing a new feature to develop
needs triage
use to identify issue needing triage from Filigran Product team
Use case
When having an intrusion set that owns an infrastructure and an infrastructure that consists of IoCs, it is not possible to access information about the IoCs while on the intrusion set page, nor is it possible to access information about the intrusion set while on the IoC page.
Current Workaround
Navigate from the Intrusion Set -> Infrastructure -> Indicator
Proposed Solution
Implement an inference rule that creates a relationship between the intrusion set and the IoCs:
Intrusion Set → uses → Infra
Indicator → indicates → infra
inferred rule: indicator → indicates → Intrusion Set
The text was updated successfully, but these errors were encountered: