Getting Started: Pivoting on Live Discover Query Results

We have recently added the ability to pivot on the results of your live discover queries. This will allow you to quickly drill down on a result from one query and use that as a parameter for another query. The system will also suggest appropriate queries for you to run based on the attribute. 

For example, after running a query on open sockets, we get a list of IP addresses. By clicking on the ellipsis beside the IP address, the menu opens up to suggest additional queries you could run to find out more related information.

It will automatically grab the IP address and plug it in as a parameter on another query.

The pivoting actions is not limited to just running additional queries. If it detects the attribute as a device name, it could trigger different actions such as scanning the device.

Here is a quick video on how to make data pivots using the results from your live discover queries. 

sophosapps-my.sharepoint.com/.../EqvTS53EZUZIqM8a1Cg1VOEBihEQD4wRaiQyrt6cH9oKhQ