You have a Microsoft Sentinel workspace named SW1.
In SW1, you investigate an incident that is associated with the following entities:
• Host
• IP address
• User account
• Malware name
Which entity can be labeled as an indicator of compromise (IoC) directly from the incident's page?
a_kto_to
3 months, 2 weeks agosapphire
7 months, 2 weeks agof6ba8a1
7 months, 3 weeks agoStudytime2023
10 months, 1 week ago90158a0
11 months, 2 weeks ago