Kaspersky Anti Targeted Attack Platform

NDR event scores and severity levels

NDR events in Kaspersky Anti Targeted Attack Platform are scored on a scale from 0.0 to 10.0.

If an NDR event is associated with a device, the application takes into account the available information about the device when calculating the score. The importance level of the device and the risks associated with this device are taken into account.

The base score specified for the NDR event type in the table of event types is used as the baseline for calculating the score.

If an NDR event is not associated with a device, the score of the event is equal to the base score.

The score determines the severity level of the NDR event. Depending on the numerical value of the score, an NDR event can have one of the following severity levels:

  • Low (scores 0.0–3.9)

    Low-severity NDR events usually do not require immediate response.

  • Medium (scores 4.0–7.9)

    Medium-severity NDR events contain information that must be looked at. These events may require a response.

  • High (scores 8.0–10.0)

    High-severity NDR events contain information that can have critical impact. These events require an immediate response.