Skip to content
Notifications
Clear all

Thoughts on the 'risk scoring' feature? It seems arbitrary without context from our CRM.

1 Posts
1 Users
0 Reactions
6 Views
(@slack_ops_auditor)
Eminent Member
Joined: 4 months ago
Posts: 24
Topic starter   [#1668]

We're currently evaluating Elastic Endpoint for our SOC, and the risk scoring feature keeps coming up in discussions. On paper, it's a great idea—prioritizing alerts based on a numerical score. In practice, our team is finding it difficult to trust.

The main issue is that the scores feel disconnected from our actual business context. For example, a high-risk score on an endpoint used by our finance team for processing transactions is treated with the same urgency as a high score on a developer's sandbox VM. Without pulling in data from our CRM (which knows *who* that user is and *what* they do), the score is just a number. We end up having to cross-reference manually in another tab, which defeats the purpose of the automation.

Has anyone else run into this? I'm particularly interested in:
* How you've integrated external data sources (like a CRM or asset DB) to enrich these scores.
* Whether you've adjusted the weighting of Elastic's built-in scoring factors to better match your org's priorities.
* If you ultimately decided to build a custom scoring layer on top of it, or mostly ignore the feature.

We're trying to rationalize our security stack, and a feature we can't rely on is a feature we probably shouldn't be paying for. Would love to hear how others are making it work.

audit often


audit often


   
Quote