Using asset-based alert correlation

Prev Next

Helix Enterprise analyzes organizational-level assets (or entities) to identify potential insider threats. It treats users and hosts as assets. Helix Enterprise detects behavior anomalies in these assets, creates detections, and alerts the system immediately.

Threats are correlated using Helix Enterprise rules, intelligence matching, and analytics. Helix Enterprise groups alerts associated with assets by entity, assesses total risk, and assigns a risk score to each asset.

Helix Enterprise provides a complete view of asset-based correlation based on available asset data and analysis and includes the following:

  • Asset-Based Alert Correlation page page —A 30-day view of user and host entities that Helix Enterprise automatically analyzed to identify potential threats. See Entity-based alert correlations.

  • Entities page—Users and hosts with detections tracked by Helix Enterprise over the last 30 days. See Entities.

  • Asset details page—Information about individual hosts or users, and related assets (if any). See Asset details.

  • Summary Dashboard—Widgets on the dashboard quantify the potential threats within your organization and the assets that post the biggest potential security threats. See Summary dashboard.

  • Index Searches—Index search has keys that allow you to build a search query based on assets. Index Search Results allows you to search based on asset attributes. See Asset-based searches.

  • Risk Assessments—Detections are captured for each type of asset. The risk score of a detection is based on the severity of the rule and the alert that was triggered. If you close an alert after assigning it to a case and investigating it, the risk score for the entity is reduced by the risk score of that detection.