Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Feature Request: additional (optional) incident response fields #73

Closed
reynas opened this issue Feb 22, 2016 · 5 comments
Closed

Feature Request: additional (optional) incident response fields #73

reynas opened this issue Feb 22, 2016 · 5 comments

Comments

@reynas
Copy link

reynas commented Feb 22, 2016

It would be nice to have a form where you have (optional) fields like

  • affected systems or computers
  • affected acounts
  • operating system
  • ...

This would give a bit more structure. Now everything is dumped in the description field.

A seperate page where we can note the contact details of the people that need to be contacted in case of an incident is welcome as well.

@tomchop
Copy link
Contributor

tomchop commented Feb 22, 2016

Thanks for your comment. We're trying to keep FIR as simple as possible, and adding such a level of details might hinder the workflow of most users. Plus, it would imply to maintain a list of computers, maybe a list of accounts, a list of valid operating systems...

We're not going to include this in our short-term roadmap but if you develop a plugin that fills your need we'll happily add it to our collection.

@ktneely
Copy link

ktneely commented Feb 26, 2016

I was thinking along these lines the other day. Instead of maintaining a list of the computers, accounts, etc., I was thinking if FIR parsed MAC address, then this could be used by a plugin to query an asset management system and pull the relevant information. This may help with further correlation and identification of at-risk targets.

@tomchop
Copy link
Contributor

tomchop commented Feb 27, 2016

Interesting. What about FIR parsing MAC addresses as "artefacts"? This way links between incidents involving the same MAC address can be established automatically.

@ktneely
Copy link

ktneely commented Mar 9, 2016

Yes, I think that would be step 1. Step 2 would be to have a plugin that can query an asset management system. I have that partially written, but am not sure how to make it into a plugin.

@tomchop
Copy link
Contributor

tomchop commented Apr 2, 2016

We need to add documentation for how to write a plugin. In the meantime maybe you can check out how other plugins are written and try to figure it out from there.
Closing this and reopening an enhancement issue for "adding MAC addresses as artefacts" (#94)

@tomchop tomchop closed this as completed Apr 2, 2016
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants