-
Notifications
You must be signed in to change notification settings - Fork 191
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Browse files
Browse the repository at this point in the history
(cherry picked from commit 494ce02) Co-authored-by: natasha-moore-elastic <[email protected]>
- Loading branch information
1 parent
7ed6567
commit b16a735
Showing
33 changed files
with
416 additions
and
26 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,77 @@ | ||
[[asset-criticality]] | ||
= Asset criticality | ||
|
||
.Requirements | ||
[sidebar] | ||
-- | ||
To view and assign asset criticality, you must: | ||
|
||
* Have the appropriate user role. | ||
* Turn on the `securitySolution:enableAssetCriticality` <<enable-asset-criticality, advanced setting>>. | ||
|
||
For more information, refer to <<ers-requirements, Entity risk scoring prerequisites>>. | ||
-- | ||
|
||
The asset criticality feature allows you to classify your organization's entities based on various operational factors that are important to your organization. Through this classification, you can improve your threat detection capabilities by focusing your alert triage, threat-hunting, and investigation activities on high-impact entities. | ||
|
||
You can assign one of the following asset criticality levels to your entities, based on their impact: | ||
|
||
* Low impact | ||
* Medium impact | ||
* High impact | ||
* Extreme impact | ||
|
||
For example, you can assign **Extreme impact** to business-critical entities, or **Low impact** to entities that pose minimal risk to your security posture. | ||
|
||
[discrete] | ||
== View and assign asset criticality | ||
|
||
Entities do not have a default asset criticality level. You can view, assign, and change asset criticality from the following places in the {elastic-sec} app: | ||
|
||
* The <<host-details-page, host details page>> and <<user-details-page, user details page>>: | ||
+ | ||
[role="screenshot"] | ||
image::images/assign-asset-criticality-host-details.png[Assign asset criticality from the host details page] | ||
|
||
* The <<host-details-flyout, host details flyout>> and <<user-details-flyout, user details flyout>>: | ||
+ | ||
[role="screenshot"] | ||
image::images/assign-asset-criticality-host-flyout.png[Assign asset criticality from the host details flyout] | ||
|
||
* The host details flyout and user details flyout in <<timelines-ui, Timeline>>: | ||
+ | ||
[role="screenshot"] | ||
image::images/assign-asset-criticality-timeline.png[Assign asset criticality from the host details flyout in Timeline] | ||
|
||
[discrete] | ||
== Improve your security operations | ||
|
||
With asset criticality, you can improve your security operations by: | ||
|
||
* <<prioritize-open-alerts, Prioritizing open alerts>> | ||
* <<monitor-entity-risk, Monitoring an entity's risk>> | ||
|
||
[discrete] | ||
[[prioritize-open-alerts]] | ||
=== Prioritize open alerts | ||
|
||
You can use asset criticality as a prioritization factor when triaging alerts and conducting investigations and response activities. | ||
|
||
Once you assign a criticality level to an entity, all subsequent alerts related to that entity are enriched with its criticality level. This additional context allows you to <<triage-alerts-associated-with-business-critical-entities, prioritize alerts associated with high-impact entities>>. | ||
|
||
[discrete] | ||
[[monitor-entity-risk]] | ||
=== Monitor an entity's risk | ||
|
||
The risk scoring engine dynamically factors in an entity's asset criticality, along with `Open` and `Acknowledged` detection alerts to <<how-is-risk-score-calculated, calculate the entity's overall risk score>>. This dynamic risk scoring allows you to monitor changes in the risk profiles of your most sensitive entities, and quickly escalate high-risk threats. | ||
|
||
To view the impact of asset criticality on an entity's risk score, follow these steps: | ||
|
||
. Open the <<host-details-flyout, host details flyout>> or <<user-details-flyout, user details flyout>>. The risk summary section shows asset criticality's contribution to the overall risk score. | ||
. Click **View risk contributions** to open the flyout's left panel. | ||
. In the **Risk contributions** section, verify the entity's criticality level from the time the alert was generated. | ||
|
||
NOTE: The risk summary and **Risk contributions** sections display an entity's asset criticality from the latest risk scoring execution. If you change the asset criticality level, subsequent risk calculations will automatically factor in the newest criticality level. | ||
|
||
[role="screenshot"] | ||
image::images/asset-criticality-impact.png[View asset criticality impact on host risks core] |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file added
BIN
+77.1 KB
docs/advanced-entity-analytics/images/assign-asset-criticality-host-details.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file added
BIN
+53.6 KB
docs/advanced-entity-analytics/images/assign-asset-criticality-host-flyout.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file added
BIN
+190 KB
docs/advanced-entity-analytics/images/assign-asset-criticality-timeline.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified
BIN
+3.88 KB
(100%)
docs/advanced-entity-analytics/images/filter-by-host-risk-level.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified
BIN
+10.6 KB
(120%)
docs/advanced-entity-analytics/images/host-details-overview.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Oops, something went wrong.