soc30 / lms
connected
splunk>enterprise
Administrator ▾Settings ▾
ES
Enterprise Security
Splunk App for Enterprise Security · v7.3.0
DAY 4 LAB · LAB 4 — MAP A CIA RISK MATRIX· week 1
Plot a CIA risk matrix using ES Risk Analysis.
  • Open Security Intelligence → top risk objects.
  • Pick 5 assets, score Likelihood × Impact (1-5).
  • Tag CIA pillar(s) violated.
  • Identify top 3 to monitor.
Hint: Risk Analysis surfaces the highest-risk objects in the org — top of the list = top of your matrix.

Security Intelligence · Risk Analysis

Highest Risk Objects (computed)
risk_objecttypesum(risk)
admin_svcuser256
10.4.12.91system240
10.4.12.50system215
akumaruser127
10.2.7.110system78
203.0.113.42system65
MITRE ATT&CK Techniques (live)
techniquecount
T11101
T1059.0011
T10711
T1021.0021
T14861
T1566.0021
T10781
T1136.0021
T1048.0031
T10401
Drill-down
Risk scores aggregate live from current notables. Run adaptive responses in the modal to see scores update.