Risk score

How a host or user accumulates risk from alerts, and how to use it.

What it is

Every entity, host, user or address, carries a risk score computed from the alerts it appears on over the last seven days: weighted by severity, decaying with age, and amplified when different rules and different sources point at the same entity. A host with one medium alert has a modest score; a host with a medium alert from Sysmon, a high alert from the firewall and a login anomaly from the identity provider has a high one.

Where it shows

The Hosts page, the Correlations page (riskiest entities), the Overview page (riskiest hosts panel) and the alert page (entity risk panel).

How to use it

Sort the queue by entity risk when severity alone does not separate the alerts. Treat a rising score on a host with no critical alert as a reason to look. Read the score together with the alerts behind it when deciding what to do.