With Jev from TypeSafe AI.
I think we can utilize it to run it against LC’s Raw Events, categorize them fast.
Creating a feature similar with ThreatLocker.
I’ve managed to set up a small test using LCQL and Jev, it managed to generate device and user based baseline after 7 days of monitoring-mode.
Just wondering, if LC team have thought of this feature or not, would be awesome! ![]()