A court-system SOC enables annotations so a risk notable lists several ATT&CK techniques contributed by different risk events. What is the purpose of those annotations on the risk story?
Select an answer to reveal the explanation.
Short Explanation
Annotations are the captions on a photo album of risk. Each contributing event keeps its ATT&CK label so the risk notable reads as a story — credential access then lateral movement — not a bare number. They do not delete detections or mint admin accounts.
Full Explanation
Risk-Based Alerting aggregates risk events onto a risk object; annotations map those detections to framework tactic and technique so the risk notable is framework-literate. Contributing events remain the evidence behind the score; annotations do not collapse them into one CIM field. They do not change ES roles or purge unannotated content. That glue is how Splunk incorporates ATT&CK into a multi-event risk story.