Overview
Cloud SIEM’s Risk Insights consolidates multiple data sources, such as SIEM threats and Cloud Security insights, into a profile representing a single security entity, such as an IAM user.
With Risk Insights, you can:
- Explore entities, filtering them by attributes such as risk score severity and configuration risks.
- View all data relevant to an entity, such as signals, misconfigurations, and identity risks.
- Triage relevant items in bulk.
- Take mitigation steps such as creating a global suppression or creating a case for an entity.
Prerequisites
Explore risk insights
Query and filter entities
On the Risk Insights Explorer, you can view all entities that have a non-zero risk score associated to them.
Quickly build context on an entity
Click an entity in the Explorer to open the entity side panel.
The What Happened section of the panel summarizes the count of signals, misconfigurations, and identity risks and how they have contributed to the risk score, as well as any potential configuration risks.
The What contributes to the score section displays the list of fired signals, relevant misconfigurations, and identity risks.
Triage and mitigate threats in bulk
The Next steps section of the entity side panel includes the available mitigation steps for SIEM signals, misconfigurations, and identity risks.
Risk scoring
An entity’s risk score approximates the entity’s risk level over the past 14 days of activity.
The risk score is calculated from the characteristics of the entity’s associated signals, such as the severity level of the signal and how many times the signal has fired.
Signal’s score impact
Each signal has a score impact. You can see a signal’s score impact in the entity panel.
Note: A signal’s score impact lasts for 2 weeks, after which the score drops to 0.
| Signal Severity | Number of points | 
|---|
| Critical | 100 | 
| High | 50 | 
| Medium | 5 | 
| LowandInfo | 0 | 
Entity’s severity threshold
The severity threshold of an entity is calculated by adding up the score impact for all signals associated with the entity.
| Entity’s Severity Threshold | Sum of the score impact for all related signals | 
|---|
| Critical | Greater than or equal to 100. | 
| High | Greater than or equal to 50and less than100. | 
| Medium | Greater than or equal to 25and less than50. | 
| Low | Greater than or equal to 10and less than25. | 
| Info | Less than 10. | 
Further reading
Additional helpful documentation, links, and articles: