We're currently evaluating Elastic Endpoint for our SOC, and the risk scoring feature keeps coming up in discussions. On paper, it's a great idea—prioritizing alerts based on a numerical score. In practice, our team is finding it difficult to trust.
The main issue is that the scores feel disconnected from our actual business context. For example, a high-risk score on an endpoint used by our finance team for processing transactions is treated with the same urgency as a high score on a developer's sandbox VM. Without pulling in data from our CRM (which knows *who* that user is and *what* they do), the score is just a number. We end up having to cross-reference manually in another tab, which defeats the purpose of the automation.
Has anyone else run into this? I'm particularly interested in:
* How you've integrated external data sources (like a CRM or asset DB) to enrich these scores.
* Whether you've adjusted the weighting of Elastic's built-in scoring factors to better match your org's priorities.
* If you ultimately decided to build a custom scoring layer on top of it, or mostly ignore the feature.
We're trying to rationalize our security stack, and a feature we can't rely on is a feature we probably shouldn't be paying for. Would love to hear how others are making it work.
audit often
audit often