Skip to content

Context-Aware Severity

Advanced tiers and above score the same rule higher in riskier context. Two fixed modifiers apply on top of a rule's severity, and both only ever raise a score — never suppress one, never lower it below the rule's stated severity, and never override a higher ML score:

  • Root principal — a rule matched by the account root identity is scaled up. This needs no configuration.
  • Untrusted source IP — a rule matched from an address outside your trusted networks is scaled up. This one is inert until you declare what "trusted" means: add your office egress, VPN, or bastion addresses under Configure → Detection Rules as severityModifiers.trustedIps (a list of exact IP strings). With no list configured, the IP modifier does nothing, so turning the tier on never silently inflates your scores.

The modifiers deliberately key only on identity and network facts — not on whether the activity is anomalous, which the ML baseline already measures — so a finding is never double-counted. A root action from an unknown IP can reach maximum severity; the same action from a trusted network scores at the rule's base.