feat: Retroactive Threat Hunting (alientvault) #1038

Open
opened 2026-03-28 04:31:05 +00:00 by mfreeman451 · 0 comments
Owner

Imported from GitHub.

Original GitHub issue: #2858
Original author: @mfreeman451
Original URL: https://github.com/carverauto/serviceradar/issues/2858
Original created: 2026-02-20T05:02:39Z


Is your feature request related to a problem?

Because we store historical NetFlow and DNS aggregates, when a new AlienVault IOC is downloaded today, core-elx can automatically run a background SRQL query against the last 90 days of TimescaleDB history to say: "We are blocking this today, but Host XYZ actually talked to this IP 3 weeks ago."

Describe the solution you'd like

A clear and concise description of what you want to happen.

Describe alternatives you've considered

A clear and concise description of any alternative solutions or features you've considered.

Additional context

Add any other context or screenshots about the feature request here.

Imported from GitHub. Original GitHub issue: #2858 Original author: @mfreeman451 Original URL: https://github.com/carverauto/serviceradar/issues/2858 Original created: 2026-02-20T05:02:39Z --- **Is your feature request related to a problem?** Because we store historical NetFlow and DNS aggregates, when a new AlienVault IOC is downloaded today, core-elx can automatically run a background SRQL query against the last 90 days of TimescaleDB history to say: "We are blocking this today, but Host XYZ actually talked to this IP 3 weeks ago." **Describe the solution you'd like** A clear and concise description of what you want to happen. **Describe alternatives you've considered** A clear and concise description of any alternative solutions or features you've considered. **Additional context** Add any other context or screenshots about the feature request here.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
carverauto/serviceradar#1038
No description provided.