-
Hi there, Within the sample DetectionSummaryEvent output in the event.PatternDispositionFlags section, there is a specific flag called "InddetMask" -- can someone provide context about what this flag means? Thanks in advance! |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 2 replies
-
Hi @dkindlund! This field represents Indicator Detection Mask and is one of the deprecated pattern disposition fields. You should be able to get the same detail using just the Pattern Disposition value (which is an integer, reference table here). I'm investigating the different times this flag would be returned as a True and will let you know what I discover. |
Beta Was this translation helpful? Give feedback.
Hi @dkindlund!
This field represents Indicator Detection Mask and is one of the deprecated pattern disposition fields. You should be able to get the same detail using just the Pattern Disposition value (which is an integer, reference table here).
I'm investigating the different times this flag would be returned as a True and will let you know what I discover.