Skip to content

v1.10.0

Compare
Choose a tag to compare
@alphasoc-bot alphasoc-bot released this 07 Jul 13:12
· 35 commits to master since this release

This update bring new fields into the incoming alerts:

  • srcMac: endpoint's MAC address
  • srcUser: user responsible for network activity
  • srcID: custom ID of the endpoint (depends on the source system)
  • connID: custom ID of the connection (depends on the source system)

As for now NFR doesn't support sending these fields from source files and only renders them for incoming alerts, so it's useful if you're sending network telemetry to AlphaSOC from elsewhere, but fetching alerts via NFR.