New Investigation Filters!

We have added two additional filters for Investigations! We brought back the Investigation Type so that you can easily filter out Investigations created by Alerts, Users, or Scheduled Forensics! We also added the MITRE ATT&CK Coverage filter as well! Instead of having to switch back to the Detection Rules MITRE ATT&CK Matrix page, or having to go into the investigation and view the evidence for MITRE info, you can now use this filter to automatically show only the investigations that correlate back to MITRE!



this is awesome man! thanks for sharing.

1 Like

Oh yeah man, always happy to share new hotness!!