drb-ra/C2IntelFeeds

Request: Add datetime to detection

friendlyc0de opened this issue · 2 comments

Hello,

Thank you for the great datasets. Is it possible to add timestamps or datetimes (UTC) to each of the detections, so that individuals or organization can better correlate, verify, and remediate any identified activity?

Thanks very much

Hi,

That data is already there on the c2_configs folder. It's the field first seen. The feed files are just rotating live date for C2s live in the last 7 or 30 days.

Hope this helps! Please let me know if I can close the issue. To add it to the feed the way the data is currently structured won't be a simple task, I can look into it but it may take a bit of time.

Thank you!

Thank you for your quick response - this makes a lot of sense, thank you for explaining the structure of the data.