Forensics Score
Severity of forensics events on workloads is used for computing the scores.

Lower score indicates:
-
One or more forensics events were observed on the workload.
-
Or one/more forensics rules are noisy and/or incorrect.
To improve the score:
-
Fix the issue if any to reduce the chances of exposures/exploits.
-
Tweak forensics rules to reduce noise and false alarms.
Forensics score for a workload is inverse function of total impact score of forensics events. Higher is the total impact score of forensics events, lower is the forensics score.
Severity |
Impact Score |
IMMEDIATE_ACTION |
100 |
CRITICAL |
10 |
HIGH |
5 |
CRITICAL |
3 |

Refer to Forensics for more details.
