Skip to content

Conversation

@janine-c
Copy link
Contributor

What does this PR do? What is the motivation?

This PR does a few things:

  • Adds a new page documenting the IOC Explorer
  • Renames a "Threat Intelligence" page to "Bring Your Own Threat Intelligence" to be more specific
  • Includes some edits for consistency and readability, like consistent case, or formatting Markdown tables to make them easier to read

Merge instructions

Please don't merge until I've gotten PM approval. Aiming for release December 19. Thank you!

Merge readiness:

  • Ready for merge

For Datadog employees:

Your branch name MUST follow the <name>/<description> convention and include the forward slash (/). Without this format, your pull request will not pass CI, the GitLab pipeline will not run, and you won't get a branch preview. Getting a branch preview makes it easier for us to check any issues with your PR, such as broken links.

If your branch doesn't follow this format, rename it or create a new branch and PR.

[6/5/2025] Merge queue has been disabled on the documentation repo. If you have write access to the repo, the PR has been reviewed by a Documentation team member, and all of the required checks have passed, you can use the Squash and Merge button to merge the PR. If you don't have write access, or you need help, reach out in the #documentation channel in Slack.

Additional notes

@janine-c janine-c requested review from a team and datamarmot as code owners December 16, 2025 22:19
@github-actions github-actions bot added the Architecture Everything related to the Doc backend label Dec 16, 2025
@janine-c janine-c added the editorial review Waiting on a more in-depth review label Dec 16, 2025
@janine-c
Copy link
Contributor Author

Created DOCS-12930 for docs team review.

@jeff-morgan-dd jeff-morgan-dd self-assigned this Dec 16, 2025
Copy link
Contributor

@jeff-morgan-dd jeff-morgan-dd left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Mostly suggestions/food for thought! Plus a few small cleanup items.

---

{{< callout url="" btn_hidden="true" header="false" >}}
The IOC Explorer is in Preview.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I can't find a guideline around capitalizing Preview/preview in our SG or Tech Content's, and i don't think we've been especially consistent (i just looked back at a few pages i knew were in preview). Lowercase seems preferable and somewhat more prevalent to me (i would also say the same for its counterpart "general availability"), and while I don't think this is a primary source of truth, it's all lowercase on this D4D page: https://datadoghq.atlassian.net/wiki/x/e4rliw.

I realize it's entirely possible and even likely that you've found precedent for capitalizing, so just calling out as a suggestion.

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for calling this out, Jeff! It's funny, when I started, it was really drilled into me that we always need to capitalize Preview, but now I can't find guidance about it either. Maybe it changed! I know the terminology around beta/preview/limited availability/etc. has changed quite a bit over time.

- Your organization must subscribe to Cloud SIEM.
- The indicator of compromise must be in a threat feed that was available to Datadog at the time of the log acquisition.
- A log that has a matching entity in threat intelligence must be acquired.
- The log must be in the time frame shown on the Explorer. The time frame is fixed to the last 30 days.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

If this is a fixed, uneditable time frame, is it more straightforward to say something like "The log must be from the last 30 days."?

(if it's not a fixed time frame, this bullet point is a bit unclear)

- A log that has a matching entity in threat intelligence must be acquired.
- The log must be in the time frame shown on the Explorer. The time frame is fixed to the last 30 days.

## Use the IOC Explorer
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I do think "Using the IOC Explorer" reads a bit more naturally. Non-critical suggestion. I know we're pretty scattered consistency-wise across the docs for using the participle form or not in these types of headings.

### Get more context on an indicator of compromise

You can click an indicator of compromise to open a side panel that contains additional information about it:
- When the indicator was first and last seen in a threat intel feed
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

"intel" is a bit informal here - I think it's fine if we're comfortable with the slight bit of vernacular since it's pretty standard usage, but just something to think about.

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actually also a bit of a potential localization concern with the shortened version, so I'd probably recommend writing out in full

Datadog collects threat intelligence across the following entity types. Each entity type has unique characteristics and a useful time frame. This time frame, or lifecycle, requires consideration when assessing the importance of a threat intelligence match on your data.

### File Hashes: Unique Digital Fingerprints
### File hashes: unique digital fingerprints
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Recommend capitalizing the first word after each colon in this and the next few headings.

TC style guide reference: https://datadoghq.atlassian.net/wiki/spaces/WRITING/pages/5341577434/Capitalization#Capitalization-for-titles-and-headings

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Architecture Everything related to the Doc backend editorial review Waiting on a more in-depth review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants