5.4 Capabilities: Scoring
The Intelligence Pipeline generates a single prioritized score for Indicators or Events. TruSTAR provides two capabilities for managing those scores within workflows.
The Intelligence Pipeline generates a single priority score for Indicators. You can fine-tune these priority scores within workflows by assigning weights to the intelligence sources used as input into the Indicator Prioritization workflow (coming in Q1 2021). This can help reduce false positive alerts by tightly managing the fidelity of the indicators you import into your workflow tools.
Priority scoring of events such as log events or SIEM alerts enables you to build automation processes into triage workflows, extending the orchestration and response capabilities of SOAR tools.