Skip to content

Scores and severity

Two numbers describe an incident, and they mean different things.

A number from 0 through 100, attached to a device and to an incident, with a history over time.

It comes from the base scores of the models that fired, and it decays — a single event does not pin a device to the top of the list indefinitely. The score history is kept, so you can see whether a device is drifting upward over a week or had one bad hour.

A score is a priority, not a probability. It answers “what should I look at first”, not “how likely is this malicious”.

A label the model declares: info, low, medium, high, critical.

Severity is a property of the kind of finding. A destination port scan is high severity whether or not it also scored well, because that class of event is worth waking up for. An hourly volume anomaly is medium severity, because that class of event is usually a backup.

During the learning phase, model results are stored with score 0 and marked as a learning baseline. A score of 0 is therefore meaningful: it says “this was evaluated and deliberately not scored”, which is different from “this was not evaluated”.

This is a small thing that matters for a dashboard you look at daily.

Severity and score are shown as coloured type, not as bars, badges, glows or pulsing animations: critical and high in the danger grade, medium in the warning grade, low and info in the muted grade; a score from 70 in the danger grade and from 40 in the warning grade.

The reason is density. One badge per severity would put four filled pills in a column and turn an incident list into a colour chart, which reads worse the longer the list gets. Status — which is a state — is a dot badge; the absence of a judgement stays a dash and gets no badge at all, because “nothing has been decided” is not a state to celebrate with a pill.

The one tinted surface in the whole product is the demo banner, and that is on purpose.

It does not trigger anything on its own. There is no threshold at which Nyxtrace acts: containment goes through a proposal that a person approves. A threat-intelligence list match is marked on the record and does not invent risk — scores remain incident-derived.