You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
We should consider adding the ability to specify whether a Findings Bundle, represents some set of data about a malware instance that was "observed" as part of an analysis run, or represents data that was derived or is otherwise "known". This mostly relevant to dynamic entities such as Actions and Behaviors, where currently this distinction is a little ambiguous (although implicit if a Findings Bundle is referenced in a corresponding Analysis).
The text was updated successfully, but these errors were encountered:
Perhaps this isn't a useful distinction to make explicitly - I'm starting to think that having the implicit Analysis -> Action/Behavior link is enough to explain whether something was observed during a particular execution or is "known" or obtained through code analysis.
We should consider adding the ability to specify whether a Findings Bundle, represents some set of data about a malware instance that was "observed" as part of an analysis run, or represents data that was derived or is otherwise "known". This mostly relevant to dynamic entities such as Actions and Behaviors, where currently this distinction is a little ambiguous (although implicit if a Findings Bundle is referenced in a corresponding Analysis).
The text was updated successfully, but these errors were encountered: