Skip to content

Search by speed #1151

@Morgan-SG

Description

@Morgan-SG

Describe the feature

If possible, we want to add a search by execution speed. If an action is performed within a certain time frame, for example 5 ms, it may be a script and not a human. And then avoid false positives.

Use Case

This option could, for example, allow us to know if a GPO is activated within a certain time period, such as a group change, etc.

Proposed Solution

A speed boost in the agents or from the SIEM itself

Other Information

No response

Acknowledgements

  • I may be able to implement this feature request
  • This feature might incur a breaking change

Metadata

Metadata

Assignees

Labels

Projects

Status

🆕 New

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions