RedELK
RedELK copied to clipboard
New alarm: new implant from a new user
Send an alarm when a new implant is detected for a user we didn't have an implant in the past.
You mean new user for the entire ops, or user-system combo?
I think new user for the entire ops would be the most beneficial. We could also make a parameter in the alarm to select the scope:
- entire ops
- per host
I agree.
Im just thinking of the added value. At least in our ops we have new implant notification done near instantly via other means. Having also RedELK do this feels redundant. And with the lower timer that RedELK alarms run, the notification will take several minutes after the fact. That having said, it prolly is not a hard alarm to make. And we can still disable it in the config. So it could not hurt.