Classify risk objects based on annotations
Ram views the annotations associated with the risk objects by accessing the Embedded Risk Workbench panels in Splunk Enterprise Security and classifies the risk objects for more targeted threat investigation. Risk workbench panels provide at-a-glance risk-based insight into the severity of the events occurring in Ram's system or network, help to prioritize notable events, assign targeted notable events to security analysts for review, and examine specific notable annotations for investigations.
By visually classifying the risk objects based on risk modifiers, risk scores, MITRE ATT&CK techniques, and tactics, Ram can identify specific adaptive response actions and streamline his threat investigation process.
- From the Enterprise Security menu, Ram selects Incident Review to display the Incident Review page and see a list of notable events for the security domains.
- Ram expands a notable event by clicking on Action next to the Risk Object, Destination, User, or Source fields.
- Ram selects the Workbench-Risk (risk_object) as Asset action.
This opens the Embedded Workbench panel that displays the following items:
- Recent risk modifiers that are applied to the risk object.
- Risk scores by artifact and trends of risk modifiers over time.
- Pie chart displaying the distribution of artifacts by MITRE ATT&CK techniques like Driven by Compromise, Account Manipulation, and so on.
- Pie chart displaying the distribution of artifacts by MITRE ATT&CK tactics like discovery, persistence, defense evasion, and so on.
- Time chart displaying the MITRE ATT&CK Techniques Over Time.
- Time chart displaying the MITRE ATT&CK Tactics Over Time.
Add annotations to enrich correlation search results
Add a risk message and a risk score to a notable
This documentation applies to the following versions of Splunk® Enterprise Security: 7.0.1, 7.0.2, 7.1.0