Skip to main content
Migration Notice
We're migrating documentation from the old portal into this one. Some things may look a little different or out of place in the meantime — we know, and we're working to get it right. If something's unclear or doesn't look right, let us know.
Version: 2.15.0

Threat Hunting FAQ

This page answers common questions about how Threat Hunting detects, scores, and labels anomalies.

How Does Threat Hunting Detect Data Exfiltration?​

Data exfiltration occurs when a user copies data. Because PowerScale does not provide a specific "copy" operation type, the system instead analyzes read and write activity. Several models examine each user's read and write patterns and establish a baseline of normal behavior using metrics such as bytesWritten, bytesRead, write frequency, and write size. When a user's behavior deviates from their typical interaction pattern, an event is reported with a confidence score that reflects the strength of the deviation.

Why Was the Severity What It Was?​

Severity is assigned automatically based on the model's internal scoring logic. See Confidence score and severity for the score bands.

Why Is This Anomaly Still Open After a Week?​

High-confidence anomalies can only be closed manually, so the model is never accidentally trained on what may be a real issue.

Why Did the System Auto-Label This Anomaly?​

It was low-confidence and no action was taken within 7 days, so the system reclassified it as expected behavior.

Will This Type of Anomaly Stop Appearing in the Future?​

It depends on the confidence level:

  • Low-confidence and auto-labeled: yes. Future retraining includes it.
  • High-confidence and still open: the model does not improve until an administrator labels it.

Can We Turn Auto-Labeling Off?​

Not currently. Auto-labeling applies only to low-confidence anomalies because they are considered non-risky. If there is a need to disable it, raise it with your engagement contact so it can be considered for a future release.

Can I Change the Confidence Level?​

Yes. The confidence threshold of 75% can be adjusted. Run the following CLI commands in Eyeglass:

igls config settings set --tag=confidence_score --value=65
sudo systemctl restart sca
warning

In the 1.0.0 and 1.1.1 releases of Threat Hunting, the filter in the Threat Hunting interface does not reflect a change to the confidence score.

What If a New User Joins the Company?​

When a new user joins and the models have not yet learned that user's behavior, all of the user's activity is still tracked, but it is not automatically flagged as anomalous. Instead, the system builds a reference baseline from the behavior of existing users and compares the new user's activity against it:

  • If the behavior aligns with the reference, no anomaly is raised.
  • If it deviates significantly, an anomaly is generated.

This approach helps reduce false positives. The new user's behavior is then included in the next model training cycle.

See Also​