
Summary
The "Correlation by Repository and Risk" rule is designed to analyze risk levels associated with various repositories by correlating detected activities with their corresponding risk scores. Although the rule has been deprecated and replaced with a more effective Risk Rule for Dev Sec Ops, it still highlights the importance of understanding patterns of high-risk activities within an organization's repositories. The rule calculates the total risk scores for each repository by summing up individual risk scores while accounting for null values. After sorting these scores, only those with scores exceeding 80 are retained, showcasing the highest-risk activities that necessitate immediate attention. This analytic is pivotal in providing insight into vulnerabilities within repositories that are frequently targeted, thereby enhancing proactive threat detection and remediation efforts. However, users must be cautious of potential false positives and take care to assess the true impact of any detected threats to prioritize appropriate responses.
Categories
- Cloud
- AWS
- Infrastructure
Data Sources
ATT&CK Techniques
- T1204.003
- T1204
Created: 2024-11-14