You have a Microsoft Sentinel workspace named SW1.
In SW1, you investigate an incident that is associated with the following entities:
• Host
• IP address
• User account
• Malware name
Which entity can be labeled as an indicator of compromise (IoC) directly from the incident's page?
a_kto_to
5 months, 1 week agosapphire
9 months agof6ba8a1
9 months, 2 weeks agoStudytime2023
12 months ago90158a0
1 year, 1 month ago