Skip to main content
Question

Entity (For eg. Domain) Enrichment & Detection Mapping

  • October 12, 2025
  • 1 reply
  • 15 views

preeeya
Forum|alt.badge.img+1

Hi All,

 

Building a native dashboard to quickly assess entity context and associated detections activity across the environment.

Would like to write a query retrieve enriched data of a particular entity (say Domain name, IP) such as first_seen_time, etc. and map all related security detections for that specified domain.

 

Thanks in advance

1 reply

preeeya
Forum|alt.badge.img+1
  • Author
  • New Member
  • October 12, 2025

Would also like to know if cases that the entity was part of can be retrieved?