Hello! Posting here on behalf of a partner who was requesting additional information from the detections page when exporting it. Here's what he said:
"Is there any way to obtain the more detailed information about each detection that is shown when clicking on the detection name, as in the screenshot below? This detail doesn't appear to be included in the CSV export, so I'm wondering whether it is available elsewhere or perhaps accessible via the API.
It would be useful to review the detections and their associated telemetry without having to manually click through potentially tens or hundreds of alerts across multiple endpoints.
The CSV export is useful for the high-level information, but it loses quite a bit of the context behind each detection. For example, being able to see that a particular detection related to an apparently free calendar application installed by a specific user, which was subsequently blocked, provides considerably more useful context than the detection and remediation status alone."