Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Feature Request: "First Seen" status to include triggering date/timestamp #32

Open
praemunio opened this issue Sep 8, 2024 · 0 comments

Comments

@praemunio
Copy link

ISSUE/CHALLENGE:
The minor challenge with this status is when reading from an archived PCAP.
As you know, RITA displays "XX hours ago" as the output,

Though this is very useful in rolling/dynamic PCAPs, it is only semi-useful in static PCAPs when correlating the displayed time to established investigatory timelines.

PROPOSED SOLUTION:
Include the triggering time/date stamp with the XX hours metric within the "First Seen" display area.

That additional information would add value for the analyst regardless of the type of analysis - static vs dynamic. Additionally, the analyst does not need to perform math to understand when it was "First Seen" unless they want to do day/date/time math while conducting their analysis ;)

Additionally, it can be leveraged as an additional check for the analyst to ensure they are reviewing and correlating evidence correctly.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant