FORTIS Logic
Overview
This page provides an explanation of how Risk Scores are calculated for various cybersecurity-related reports in Power BI. These scores are designed to help prioritize security events based on severity, action type, and IP classifications.
Risk Score Range
Detected malware or direct threat activity.
Strong indicators of potentially malicious behavior.
Suspicious behavior needing further investigation.
Benign but logged for visibility.
General activity.
Report - Key Conditions
Anti-Malware Report
| Firewall Action | Event Type | Source/Destination IP | Risk Score |
|---|---|---|---|
| detected / monitored / passthrough / forward | NOT in excluded list* | - | 5 |
| blocked / dropped / drop | - | Both are private | 4 |
| blocked / dropped / drop | - | - | 2 |
| All Other | - | - | 1 |
| No logs | - | - | 1 |
Excluded Event Types*
- FortiGate-antivirus-file-oversize
- FortiGate-antivirus-scan-archive-oversize-notif
- FortiGate-antivirus-scan-archive-corrupted-notif
- FortiGate-antivirus-file-submitted
- FortiGate-antivirus-scan-archive-multipart-notif
- FortiGate-antivirus-file-monitored
IDS / IPS Report
| Firewall Action | Severity | Source/Destination IP | Risk Score |
|---|---|---|---|
| Allowed / Detected / Alert / <blank> | "Critical" / "High" / "1" | — | 5 |
| Blocked / Block / Dropped / Drop | Not "Low" / not "Informational" / not "3" | Both are private | 4 |
| Allowed / Detected / Alert / <blank> | "Medium" / "2" | — | 3 |
| Others | — | — | 1 |
| Any | No Logs | N/A | 5 |
Web Filter Report
| Firewall Action | WF Security Risk | Count | Risk Score |
|---|---|---|---|
| Passthrough / Allowed / forward | Yes | > 10,000 | 5 |
| Passthrough / Allowed / forward | Yes | <= 10,000 | 4 |
| Blocked / drop | Yes | - | 3 |
| Blocked / drop | No | - | 2 |
| Passthrough / Allowed / forward | No | - | 1 |
| No Logs | - | - | 5 |
Application Control Report
| Firewall Action | AppCtrl Security Risk | Count | Risk Score |
|---|---|---|---|
| Pass / allow / forward / NA / <blank> | Yes | > 10,000 | 5 |
| Pass / allow / forward / NA / <blank> | Yes | <= 10,000 | 4 |
| Block / drop | Yes | Any | 3 |
| Block / drop | No | Any | 2 |
| Pass / allow / forward / NA / <blank> | No | Any | 1 |
| No Logs | N/A | Any | 5 |
Firewall Config Changes Report
| Source IP | Risk Score |
|---|---|
| Public IP | 3 |
| Private IP | 1 |
| No Logs | 1 |
Credentials Compromise Report
| Condition | Risk Score |
|---|---|
| Account compromises found with password hits | 4 |
| Account compromises found without password hits | 2 |
| No compromises found | 1 |
EDR Report
| Event Severity | Process Blocked | Risk Score |
|---|---|---|
| 9, 10 | Not "True" | 5 |
| 9, 10 | "True" | 4 |
| 6, 7, 8 | Not "True" | 4 |
| 6, 7, 8 | "True" | 3 |
| 3, 4, 5 | Not "True" | 3 |
| 3, 4, 5 | "True" | 2 |
| All other | - | 1 |
| No Logs | - | 1 |
| Severity | Event Type Group | Event Type | Risk Score |
|---|---|---|---|
| Any | Any | confirmedCompromised | 5 |
| 9, 10 | Not "Info" / Not "Suspicious Logon" | Not "confirmedCompromised" | 5 |
| 6, 7, 8 | Not "Info" / Not "Suspicious Logon" | Not "confirmedCompromised" | 4 |
| 4, 5 | Not "Info" / Not "Suspicious Logon" | Not "confirmedCompromised" | 3 |
| 2, 3 | Not "Info" / Not "Suspicious Logon" | Not "confirmedCompromised" | 2 |
| All other | - | - | 1 |
| No Logs | - | - | 1 |
| Firewall Action | Event Classifier | Risk Score |
|---|---|---|
| Not "blocked" | Malicious | 5 |
| "blocked" | Malicious | 4 |
| Not "blocked" | Suspicious, PUP | 3 |
| "blocked" | Suspicious, PUP | 2 |
| All other | - | 1 |
| No Logs | - | 1 |
| Event Type | Risk Score |
|---|---|
| New_Threat_Not_Mitigated / Threat_Mitigation_Report_Quarantine_Failed / Threat_Mitigation_Report_Kill_Failed / Threat_Mitigation_Report_Remediate_Failed | 5 |
| New_Threat_Suspicious | 3 |
| Threat_Mitigation_Report_Kill_Success / Threat_Mitigation_Report_Quarantine_Success / Threat_Mitigation_Report_Remediate_Success / New_Threat_Preemptive_Block / New_Threat_Mitigated | 2 |
| No Logs | 1 |
| Threat Level | Firewall Action | Risk Score |
|---|---|---|
| Critical | Allow / No action | 5 |
| Critical | Would Block | 4 |
| Critical | Blocked | 3 |
| Alert | Continue Scanning / Replaced | 3 |
| Notice | ATP would clean / ATP would block / ATP would contain | 2 |
| Notice | Clean / None | 1 |
| Warning | Deny access / Not Applicable / None | 1 |
| Information | None / Blocked | 1 |
| No logs | - | 1 |
FW Bandwidth Report
Security Risk References
WebFilter Security Risk
The following references are considered security risks and affect the risk score for the mentioned reports.
44 referencesAppCtrl Security Risk
The following references are considered security risks and affect the risk score for the mentioned reports.
10 references
Are you protected?
Connect with our experts to start your Cybersecurity Assessment.
LCM -A Leader In Security
Stay updated with the latest news and trends in cybersecurity