fsf icon indicating copy to clipboard operation
fsf copied to clipboard

thresholding for alerting

Open akniffe1 opened this issue 7 years ago • 0 comments

Rather than alerting only when a yara sig or jq sig has the alert condition set, it would be very helpful to also allow for thresholded alerting wherein one could establish in the dispositioner a relative "suspiciousness" on a score of -10 to +10 for a yara sig or post processor sig and also set an alerting threshold so that a series of relatively suspicious things could trigger an alert or archival decision.

akniffe1 avatar Apr 08 '17 00:04 akniffe1