Hello!
I am a bit confused about applying criterias of Severity and Confidence
Current settings are like this:
-Active Protections - Severity - Medium and above
-Activation mode:
High Confidence-Prevent,
Medium Confidence-Prevent
Low Confidence-Detect
I noticed a security event at a customer with Confidence-Low and Severity-Critical . The action was Detect, despite the Severity being Critical (so included in Medium and above).
So even if Severity is above threshold, it still only activates if the Confidence level is met?
Is there a way to activate the Prevent action with Low Confidence setting when Severity level alone meets the set thresold? Or do you think that would still cause a lot of false positives.