{{#if ANALYST_STATE_PRESENTATION}} {{#if HAS_MDR_ENTITLEMENT}}
Managed Detection and Response has determined an alert to be an {{ANALYST_STATE_PRESENTATION}}.
{{else if HAS_MTH_ENTITLEMENT}}Managed Threat Hunting has determined an alert to be an {{ANALYST_STATE_PRESENTATION}}.
{{else}}Managed Detection and Response has determined an alert to be an {{ANALYST_STATE_PRESENTATION}}.
{{/if}} {{/if}} {{#if links}}{{linksLabel}} |
{{ this.label }} |
{{INCIDENT_SUMMARY}}
{{else if REASON}}{{REASON}}
{{/if}}Device | {{DEVICE_NAME}} |
Device username | {{DEVICE_EMAIL}} |
Policy | {{DEVICE_GROUP_NAME}} |
Policy ID | {{POLICY_ID}} |
Target value | {{TARGET_VALUE}} |
Alert type | {{MDR_ALERT_TYPE}} |
Alert severity | {{THREAT_SCORE}} |
Alert ID | {{INCIDENT_ID}} |
Alert created | {{LAST_UPDATE_TIME}} |
Watchlist | {{#each WATCHLISTS}} {{this.name}} {{#unless @last}},{{/unless}} {{/each}} |
MDR workflow | {{ANALYST_TRIAGE_INFO_PRESENTATION}} |
MDR determination | {{ANALYST_STATE_PRESENTATION}} |
Process | {{APPLICATION_NAME}} |
Process path | {{PROCESS_PATH}} |
Reputation | {{REPUTATION}} |
Process username | {{PROCESS_USER_NAME}} |
Process SHA-256 | {{SHA256_HASH}} |
Parent process | {{PARENT_PROCESS_NAME}} |
Parent process username | {{PARENT_PROCESS_USER_NAME}} |
Parent process SHA-256 | {{PARENT_PROCESS_SHA256_HASH}} |