Skip to content
Notifications
Clear all

Just built a simple scoring system to rank intel by our asset exposure

1 Posts
1 Users
0 Reactions
33 Views
(@integration_ian)
Honorable Member
Joined: 5 months ago
Posts: 396
Topic starter   [#19497]

Just got tired of our SOC drowning in generic threat intel feeds. We get hundreds of Mandiant alerts daily, but 95% are irrelevant to our actual tech stack. Building custom logic for every alert is a time sink.

Built a simple scoring system that sits between Mandiant's feed and our SIEM. It cross-references each piece of intel against our CMDB and vulnerability scan data, then assigns a priority score. Now the team only gets escalated alerts that actually matter.

The core logic is straightforward. We pull in the Mandiant data (usually via their API), then run it through a mapping script. Key factors:

* **Asset Match Score:** Does the intel target an OS/software we have? (+10 per match)
* **Exposure Score:** Is the affected asset internet-facing? (+15 if yes)
* **Patch Status:** Is it unpatched in our vuln scan? (+20 if yes)
* **Mitigation Score:** Do we already have a compensating control (WAF rule, IPS signature)? (-15 if yes)

Here's a simplified version of the scoring logic we wrote in Python:

```python
def score_intel(threat_report, asset_inventory):
score = 0
# Check for software/OS matches
for our_asset in asset_inventory:
if threat_report['target_software'] in our_asset['software']:
score += 10
if our_asset['internet_facing']:
score += 15
if our_asset['unpatched']:
score += 20
# Apply mitigation discounts
if threat_report['mitigation_id'] in active_mitigations:
score -= 15
return score
```

Anything scoring below 10 gets tagged for weekly review. Over 25 triggers an immediate SIEM alert and ticket.

This isn't revolutionary, but it automates the tedious "do we care?" decision. Before, it was all manual lookups. Now the feed is prioritized. Considering porting this logic into a Workato recipe to handle the enrichment and scoring before the data even hits the SIEM. Has anyone else built something similar? Curious how you're handling the asset data mapping—that's still a bit brittle for us.


Integration is not a project, it's a lifestyle.


   
Quote