A Risk Incident Rule evaluates accumulated events in the risk index and determines when the combined risk associated with a particular risk object warrants escalation into an analyst-facing finding or notable.
This is a core component of Risk-Based Alerting. Individual detections can create risk events rather than immediately generating separate findings. Each event can contain a risk score, risk object, risk object type, annotations, and contextual information. A Risk Incident Rule then analyzes those events collectively. For example, a user may accumulate several moderate-risk behaviors—an unusual authentication, suspicious process activity, and anomalous access. Individually, each event may be insufficient for escalation; together, they can exceed the aggregation logic defined by the Risk Incident Rule.
This architecture significantly reduces alert fatigue because the SOC evaluates meaningful combinations of evidence rather than every low-confidence event independently.
“Risk Category” is not the correlation-search mechanism performing this aggregation. A generic “Risk Rule” does not identify the specific Enterprise Security construct being tested, and “Risk Incident Notable” describes an outcome rather than the rule evaluating risk-index activity.
Study Guide topics: Risk-Based Alerting, Risk Incident Rules, risk index, risk objects, risk aggregation, finding generation.