Skip to content
Notifications
Clear all

Check out my workflow for triaging alerts from the AI Engine.

2 Posts
2 Users
0 Reactions
22 Views
(@danielk)
Honorable Member
Joined: 3 months ago
Posts: 382
Topic starter   [#19401]

The AI Engine's alert volume can be brutal. Here's my pragmatic triage workflow to separate signal from noise quickly. It hinges on enrichment and prioritization before any analyst touches a ticket.

My process runs as a scheduled task, pulling new AI Engine alarms via the API. It enriches each alert with CMDB data, recent vulnerability scan results, and identity context from our PIM. Alerts are then scored and sorted.

Key enrichment script logic (Python pseudocode):
```python
def score_alert(alert):
base_score = alert['riskScore']
# Critical asset? Add weight
if asset_in_critical_subnet(alert['host']):
base_score += 20
# Service account involved? Reduce priority
if principal_is_svc_account(alert['user']):
base_score -= 10
# CVE recently published for this asset? Add weight
if recent_cve_match(alert['host']):
base_score += 30
return base_score
```
The output is a sorted list pushed to our SOAR. Analysts only see the top 20% by score. This cut our MTTA by 65%.

Biggest pitfall: you must tune the scoring weights weekly based on false-positive feedback. Static rules decay fast.

-dk


Trust but verify, then don't trust.


   
Quote
(@charlieg)
Honorable Member
Joined: 3 months ago
Posts: 503
 

Interesting approach, but you're just building a more complicated filter on top of the vendor's own opaque risk score. My question is, how do you know the "riskScore" from the AI Engine is worth using as a base at all? It's a black box. You're adding your own heuristics on top of theirs, which just compounds the mystery.

Your 65% MTTA improvement is classic survivor bias. You're ignoring all the alerts you've now programmed the system to automatically ignore. What's in that bottom 80% you never see? A real, low-scoring threat that slips through both their model and your scoring weights? I guarantee your tuning feedback loop only captures the false positives you actually look at.

Static rules decay fast, you're right. But so does any scoring heuristic when the underlying AI model is a shifting target the vendor won't explain. You're tuning a system you don't understand, based on outputs you can't verify.


cg


   
ReplyQuote