Open
Description
To facilitate future analysis of alerts it would be interesting to include the root and all extracted files as a single elastic field in the alert.
There is a choice to be made whether to simply include the hash or whether this is a list of sub-documents that include the hash, size, type or other metadata about the file.