ocsf-schema
ocsf-schema copied to clipboard
Adding additional objects to Evidence Artifacts in Detection Findings
Detection Finding
's Evidence Artifacts
represent collection of Evidences associated to the activity, that's why it should contain all possible objects that can be a part of detections or activity.
Now this list contains only this objects:
- api
- actor
- connection_info
- query
- dst_endpoint
- file
- process
- src_endpoint
We have additional objects that can be added to this list:
- account
- device
- url
- user
I'd suggest also to move Cloud
and Resources
to be a part of Evidence Artifact
's as well, to make it with straight logic.