-
Notifications
You must be signed in to change notification settings - Fork 1.2k
Add IOC Explorer doc; small edits #33413
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: master
Are you sure you want to change the base?
Conversation
Preview links (active after the
|
|
Created DOCS-12930 for docs team review. |
jeff-morgan-dd
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Mostly suggestions/food for thought! Plus a few small cleanup items.
| --- | ||
|
|
||
| {{< callout url="" btn_hidden="true" header="false" >}} | ||
| The IOC Explorer is in Preview. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I can't find a guideline around capitalizing Preview/preview in our SG or Tech Content's, and i don't think we've been especially consistent (i just looked back at a few pages i knew were in preview). Lowercase seems preferable and somewhat more prevalent to me (i would also say the same for its counterpart "general availability"), and while I don't think this is a primary source of truth, it's all lowercase on this D4D page: https://datadoghq.atlassian.net/wiki/x/e4rliw.
I realize it's entirely possible and even likely that you've found precedent for capitalizing, so just calling out as a suggestion.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks for calling this out, Jeff! It's funny, when I started, it was really drilled into me that we always need to capitalize Preview, but now I can't find guidance about it either. Maybe it changed! I know the terminology around beta/preview/limited availability/etc. has changed quite a bit over time.
| - Your organization must subscribe to Cloud SIEM. | ||
| - The indicator of compromise must be in a threat feed that was available to Datadog at the time of the log acquisition. | ||
| - A log that has a matching entity in threat intelligence must be acquired. | ||
| - The log must be in the time frame shown on the Explorer. The time frame is fixed to the last 30 days. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
If this is a fixed, uneditable time frame, is it more straightforward to say something like "The log must be from the last 30 days."?
(if it's not a fixed time frame, this bullet point is a bit unclear)
| - A log that has a matching entity in threat intelligence must be acquired. | ||
| - The log must be in the time frame shown on the Explorer. The time frame is fixed to the last 30 days. | ||
|
|
||
| ## Use the IOC Explorer |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I do think "Using the IOC Explorer" reads a bit more naturally. Non-critical suggestion. I know we're pretty scattered consistency-wise across the docs for using the participle form or not in these types of headings.
content/en/security/cloud_siem/triage_and_investigate/ioc_explorer.md
Outdated
Show resolved
Hide resolved
content/en/security/cloud_siem/triage_and_investigate/ioc_explorer.md
Outdated
Show resolved
Hide resolved
| ### Get more context on an indicator of compromise | ||
|
|
||
| You can click an indicator of compromise to open a side panel that contains additional information about it: | ||
| - When the indicator was first and last seen in a threat intel feed |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
"intel" is a bit informal here - I think it's fine if we're comfortable with the slight bit of vernacular since it's pretty standard usage, but just something to think about.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Actually also a bit of a potential localization concern with the shortened version, so I'd probably recommend writing out in full
content/en/security/cloud_siem/triage_and_investigate/ioc_explorer.md
Outdated
Show resolved
Hide resolved
content/en/security/cloud_siem/triage_and_investigate/ioc_explorer.md
Outdated
Show resolved
Hide resolved
| Datadog collects threat intelligence across the following entity types. Each entity type has unique characteristics and a useful time frame. This time frame, or lifecycle, requires consideration when assessing the importance of a threat intelligence match on your data. | ||
|
|
||
| ### File Hashes: Unique Digital Fingerprints | ||
| ### File hashes: unique digital fingerprints |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Recommend capitalizing the first word after each colon in this and the next few headings.
TC style guide reference: https://datadoghq.atlassian.net/wiki/spaces/WRITING/pages/5341577434/Capitalization#Capitalization-for-titles-and-headings
Co-authored-by: jeff-morgan-dd <[email protected]>
What does this PR do? What is the motivation?
This PR does a few things:
Merge instructions
Please don't merge until I've gotten PM approval. Aiming for release December 19. Thank you!
Merge readiness:
For Datadog employees:
Your branch name MUST follow the
<name>/<description>convention and include the forward slash (/). Without this format, your pull request will not pass CI, the GitLab pipeline will not run, and you won't get a branch preview. Getting a branch preview makes it easier for us to check any issues with your PR, such as broken links.If your branch doesn't follow this format, rename it or create a new branch and PR.
[6/5/2025] Merge queue has been disabled on the documentation repo. If you have write access to the repo, the PR has been reviewed by a Documentation team member, and all of the required checks have passed, you can use the Squash and Merge button to merge the PR. If you don't have write access, or you need help, reach out in the #documentation channel in Slack.
Additional notes