For e.g. for mandiant, connector can be built easily or the same can be configured as feed.
What is the best design choice in this case and why ?
I assume yara-l rules may not work on alerts consumed with soar connector. Are there any other factors that should be considered while making this decision ?
Thanks