Was the idea of the MVISION EDR product team that a SOC analyst always has the console open and observes the monitoring alerts all the time?
The MVISION API just offers options for EDR search and investigation for automation. Are there any plans to extend the API for EDR monitoring events (high/medium/low) or EDR alerting events (high/medium)?
Would it be possible to create and automated reaction for high-risk alerts that sends an event to ePO on-prem via DXL for further notification?
We are also missing a notification feature like https://community.mcafee.com/t5/MVISION-EDR/MVISION-EDR-email-notifications/m-p/693703
Please share your plans of the product team.