3 minute read
You can find the reporting dashboard under https://reporting.plussecurity.io - click “Sign in with SSO” to sign in via your known Customer IDM credentials.
After logging in, only authorizations for the “Main Org” are available to you by default. The authorizations for other organizations or areas must be set up manually for each user.
To activate the users, please open a service request via our Help Desk and enter the user name and the corresponding e-mail address.
Once you have been activated, you can select your organization in the top left-hand corner. Don’t worry - the “Main Org” is the default organization and does not contain any content.
You will find the following dashboards under the burger menu:
Use the time selection at the top right to set the desired time range for the data display (see image below):
This dashboard shows an overview of the computers in the EDR.
This dashboard shows insights into the EDR platform, current alarms and rules that have been triggered.
The severity of an incident is calculated based on relevance, credibility and severity:
Relevance: Indicates how much the incident could affect your network. For example, an open port has a high relevance as it is a potential gateway for attacks.
Credibility: Describes the reliability of the incident, based on the credibility rating of the log source. Credibility increases when multiple sources report the same incident.
Severity: Evaluates the threat level that the source represents in relation to the target’s defense readiness. A poorly protected target leads to a higher severity level.
These factors are combined to assess the overall severity of the incident and prioritize appropriate countermeasures.
This dashboard shows insight of the SOC, current offenses and an overview of data that is currently residing inside the SOC.