Software Secure Workload
Activity Configure

Forensics Score

Severity of forensics events on workloads is used for computing the scores.

Forensics Score Details
Figure 1: Forensics Score Details

Lower score indicates:

  • One or more forensics events were observed on the workload.

  • Or one/more forensics rules are noisy and/or incorrect.

To improve the score:

  • Fix the issue if any to reduce the chances of exposures/exploits.

  • Tweak forensics rules to reduce noise and false alarms.

Forensics score for a workload is inverse function of total impact score of forensics events. Higher is the total impact score of forensics events, lower is the forensics score.

Severity

Impact Score

IMMEDIATE_ACTION

100

CRITICAL

10

HIGH

5

CRITICAL

3

Forensics Score Formula
Figure 2: Forensics Score Formula

Refer to Forensics for more details.

Help for Forensics Score
Figure 3: Help for Forensics Score