You have a Microsoft Sentinel workspace named SW1.
In SW1, you investigate an incident that is associated with the following entities:
• Host
• IP address
• User account
• Malware name
Which entity can be labeled as an indicator of compromise (IoC) directly from the incident's page?
a_kto_to
1 week agosapphire
4 months agof6ba8a1
4 months, 1 week agoStudytime2023
6 months, 4 weeks ago90158a0
8 months, 1 week ago