A risk notable for a city finance user lists annotations from several contributing risk events, each mapping a different ATT&CK technique. What is the intended use of that stacked view?
Select an answer to reveal the explanation.
Short Explanation
Several sticky notes on one finance-user risk notable are the chapter titles, not a bug. Each contributing event brought its ATT&CK technique along, so the analyst can read the story — phish, then mailbox rule, then odd login — in one place. That stack is the point of annotations on risk notables.
Full Explanation
Risk notables aggregate contributing risk events on a risk object such as a city finance user. Annotations from those events can show different ATT&CK techniques, which is intended: a readable multi-technique story of how risk accumulated. Multiple techniques do not mean annotations are broken, that contributing events should drop metadata, or that the SOC should fall back to hash lookups only. Defense Analysts should use the stacked annotations to prioritize the next investigative pivot on that identity.