FORTIS Logic

Overview

This page provides an explanation of how Risk Scores are calculated for various cybersecurity-related reports in Power BI. These scores are designed to help prioritize security events based on severity, action type, and IP classifications.

Score Range

•        Risk Score 5 – Critical: Detected malware or direct threat activity.

•        Risk Score 4 – High: Strong indicators of potentially malicious behavior.

•        Risk Score 3 – Medium: Suspicious behavior needing further investigation.

•        Risk Score 2 – Low: Benign but logged for visibility.

•        Risk Score 1 – Informational: General activity.


Anti-Malware Report

Explanation of Key Conditions

Excluded Event Types:

  • FortiGate-antivirus-file-oversize

  • FortiGate-antivirus-scan-archive-oversize-notif

  • FortiGate-antivirus-scan-archive-corrupted-notif

  • FortiGate-antivirus-file-submitted

  • FortiGate-antivirus-scan-archive-multipart-notif

  • FortiGate-antivirus-file-monitored


IDS/IPS Report

Explanation of Key Conditions


Web Filter Report

Explanation of Key Conditions


Application Control Report

Explanation of Key Conditions


Firewall Config Changes Report

Explanation of Key Conditions


WebFilter Security Risk

AI-data-and-workflow-optimizer

AI-website-generator

Academic Fraud,Cheating and Plagiarism

Adware,Software/Technology,Computers and Internet

Artificial Intelligence Technology

Command and Control

Crypto Mining

Cryptomining

Dynamic DNS

Hacking

Illegal Downloads

Illegal or Unethical

Malicious Websites

Malware

Malware,Phishing

Newly Observed Domain

Newly Registered Domain

P2P/File sharing

Parked Domains

Peer-to-peer File Sharing

Personal VPN

Phishing

Potentially Unwanted Program

Proxy Avoidance

Proxy/Anonymizer,Allow List,Encrypted DNS

Remote Access

artificial-intelligence

hacking

AppCtrl Security Risk

  • Email

  • P2P

  • Remote.Access

  • Storage.Backup

  • Proxy

Overall Category Risk Scoring

To determine an organization's overall risk level for each report category (e.g., Anti-Malware, App Ctrl, IDS/IPS, Web Filter), we identify the most severe event recorded and use that as the representative score for that category.

Page last updated: July 2025