Skip to content

[Security][Detections] Ability to adjust multiple Risk Score settings and define action within a single Detection Rule #86306

Open

Description

Describe the feature:
Ability to manually or auto adjust multiple Risk score settings and define an action within a single detection rule

Describe a specific use case for the feature:
In the example below, I am starting with a high severity detection with a risk score of 73. When I override the severity, with low and medium events, there is no way to adjust the risk score numbers for both of these overrides.

It is also not possible to define an action, based on the severity. For example, if we want an email to be sent only for high severity events. It should be possible to define an action which only triggers if some condition is met (for example signal.rule.severity : high)

After speaking to a colleague, it was mentioned the risk score override only supports a single value exact match against number fields, so pretty limited in its current state.

A couple potential options -

  1. allow the user to manually specially the risk score for each override (multiple)
  2. automatically adjust the risk score based on the overrides severity (i.e low = 21, medium = 47, high = 73, critical = 100)

image

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Assignees

No one assigned

    Labels

    Feature:Rule ActionsSecurity Solution Rule Actions featureFeature:Rule CreationSecurity Solution Detection Rule CreationTeam: SecuritySolutionSecurity Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.Team:Detection EngineSecurity Solution Detection Engine AreaTeam:Detections and RespSecurity Detection Response TeamTheme: simp_prot_mgmtSecurity Solution Simplified Protection Management ThemeenhancementNew value added to drive a business result

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions