Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add context-awareness to alert severity #1455

Open
YamatoSecurity opened this issue Oct 16, 2024 · 0 comments
Open

Add context-awareness to alert severity #1455

YamatoSecurity opened this issue Oct 16, 2024 · 0 comments
Labels
enhancement New feature or request under-investigation under investigation to develop

Comments

@YamatoSecurity
Copy link
Collaborator

Severity should be effected by how sensitive a system is. For example a Mimikatz infection is much more serious when found on a domain controller than it is found on a normal user's workstation that contains little to no sensitive information.
So I would like to add an option to read in a list of hostnames considered sensitive (ex: DCs, file servers, domain admin machines, etc...) and bump up the alert severity level for each alert. (info will still stay the same, but low alerts will become medium, etc.. I am wondering what to do after critical though, -> fatal?)

I think most people won't know which machines are sensitive so it would be nice to automate this. Certain events only happen on DCs, file servers, etc.. so we could first scan for these events and then automatically generate a list of DCs and file servers.

@YamatoSecurity YamatoSecurity added enhancement New feature or request under-investigation under investigation to develop labels Oct 16, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request under-investigation under investigation to develop
Projects
None yet
Development

No branches or pull requests

1 participant