Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

thresholding for alerting #51

Open
akniffe1 opened this issue Apr 8, 2017 · 0 comments
Open

thresholding for alerting #51

akniffe1 opened this issue Apr 8, 2017 · 0 comments
Milestone

Comments

@akniffe1
Copy link
Collaborator

akniffe1 commented Apr 8, 2017

Rather than alerting only when a yara sig or jq sig has the alert condition set, it would be very helpful to also allow for thresholded alerting wherein one could establish in the dispositioner a relative "suspiciousness" on a score of -10 to +10 for a yara sig or post processor sig and also set an alerting threshold so that a series of relatively suspicious things could trigger an alert or archival decision.

@akniffe1 akniffe1 added this to the 2.0 milestone Apr 8, 2017
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant