Skip to content

Commit e48ce70

Browse files
Travis TrimboliTravis Trimboli
authored andcommitted
docs: updated the how-to README
1 parent 09a860a commit e48ce70

1 file changed

Lines changed: 1 addition & 0 deletions

File tree

docs/how-to/README.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -21,6 +21,7 @@ Pick the guide for your goal — no need to read them in order.
2121
| [Build Cross-Platform Investigations](build-investigations.md) | Collect and correlate evidence from multiple platforms into a unified evidence graph |
2222
| [Create Intelligence Reports](create-intelligence-reports.md) | Author structured intelligence products with a formal lifecycle and STIX 2.1 export |
2323
| [Disseminate Intelligence](disseminate-intelligence.md) | Export, webhook notifications, TAXII 2.1 serving, and REST API gateway |
24+
| [Incident to Campaign Intelligence](incident-to-campaign-intelligence.md) | Triage XSOAR incidents, enrich with Splunk, Entra ID, CrowdStrike, Shodan, VirusTotal, Recorded Future, and ThreatQ, correlate incidents into a campaign, and publish a structured report |
2425
| **Phase 4 — Control, Reasoning, Safety** | |
2526
| [Use the Execution Context](use-execution-context.md) | Create and propagate `ExecutionContext`; enforce domain boundaries and trust levels; track query budgets |
2627
| [Use the Reasoning Engine](use-reasoning-engine.md) | Score and rank observables; propose, evaluate, and close hypotheses; track negative evidence |

0 commit comments

Comments
 (0)