Decision Tree V0
The questions Raksa asks before it pre-decides, per attack category.
V0 draft: to be validated with Protergo.
Signals per outcome
False Positive
- · Few failures then a success by the same user
- · Typo pattern in username
- · No reputation hits
Exclusion / Whitelist
- · svc_ account from backup host
- · Same 02:00 window every night
- · Change ticket on file
Open Ticket
- · Success after many failures
- · Source on 2+ threat feeds
- · Many usernames tried (spraying)
Edge cases
- · Admin rotating passwords triggers bursts
- · VPN gateway NAT hides real source
Raksa declines to pre-decide when
- · No auth logs retained for the target host
- · Source IP is a shared NAT with no user mapping
Version history
+ Brute Force: added 'success after failures' check (from 4 overrides)~ Scanning: scanner IP list now read from DCI asset register- Removed 'port count > 1000' question, it never changed the outcome