RedELK icon indicating copy to clipboard operation
RedELK copied to clipboard

💡 Add the possibility to "flag" key events

Open fastlorenzo opened this issue 3 years ago • 1 comments

It would be great to be able to "flag" (with tags maybe?) some key documents, and potentially add a small description. This would be useful to be able to extract a high level timeline of the attack for reporting.

Maybe this could be done via the Kibana plugin (I'll investigate that one).

@MarcOverIP / @xychix let me know what you think about the idea 💡

fastlorenzo avatar May 08 '21 21:05 fastlorenzo

Would be a great addition. Really love that functionality if it's GUI clickable in Kibana.

I believe @xychix has done something internally with jupyter notebooks.

MarcOverIP avatar May 24 '21 14:05 MarcOverIP