-
Notifications
You must be signed in to change notification settings - Fork 50
Open
Labels
needs-triageNeeds to be triagedNeeds to be triaged
Description
Describe the feature
If possible, we want to add a search by execution speed. If an action is performed within a certain time frame, for example 5 ms, it may be a script and not a human. And then avoid false positives.
Use Case
This option could, for example, allow us to know if a GPO is activated within a certain time period, such as a group change, etc.
Proposed Solution
A speed boost in the agents or from the SIEM itself
Other Information
No response
Acknowledgements
- I may be able to implement this feature request
- This feature might incur a breaking change
Metadata
Metadata
Assignees
Labels
needs-triageNeeds to be triagedNeeds to be triaged
Type
Projects
Status
🆕 New