Risk Scoring

Modules Tab

Modules Tab

Where: /dev/org-control/risk-configurationModules tab

The Modules tab lets you view and manage the scoring modules for your organization. Each module represents a security domain that gets its own score.


What You See

A table listing all configured modules. Each row shows the module's details:

Column What It Shows
Name Module name (e.g., "Brand Protection", "Attack Surface Management")
Collector Key The internal identifier (ASM, BP, DETECTION)
Weight How much this module contributes to the overall score (e.g., 40%)
Enabled Whether this module is active in scoring
Formula Which formula is linked to this module

What Are Modules?

Each module watches a different area of security:

Module What It Monitors
Attack Surface Management (ASM) Vulnerabilities, exposed ports, subdomains — infrastructure risk
Brand Protection (BP) Phishing sites, dark web mentions, leaked credentials, scams — brand abuse
General Detection Unclassified detections awaiting triage

Module Weights

Weights control how much each module affects the overall score. Weights must add up to 100%.

Example:

  • ASM: 40% — infrastructure risk has the biggest influence
  • BP: 35% — brand abuse is a close second
  • Detection: 25% — unclassified items matter less

If a customer's primary concern is brand abuse, you'd increase BP's weight and decrease the others.


Editing a Module

Click a module row to open the Module Editor side panel where you can:

  • Change the module name and description
  • Adjust the weight
  • Enable or disable the module
  • Link a different formula

After saving, the next scoring run will use the updated settings.


Adding a Module

Click the "Add Module" button above the table to create a new module definition. This is typically done during initial setup and is rare after that.

Note: Modules are usually auto-created when scoring runs for the first time. You'll rarely need to add one manually.

Where: /dev/org-control/risk-configurationModules tab

The Modules tab lets you view and manage the scoring modules for your organization. Each module represents a security domain that gets its own score.


What You See

A table listing all configured modules. Each row shows the module's details:

Column What It Shows
Name Module name (e.g., "Brand Protection", "Attack Surface Management")
Collector Key The internal identifier (ASM, BP, DETECTION)
Weight How much this module contributes to the overall score (e.g., 40%)
Enabled Whether this module is active in scoring
Formula Which formula is linked to this module

What Are Modules?

Each module watches a different area of security:

Module What It Monitors
Attack Surface Management (ASM) Vulnerabilities, exposed ports, subdomains — infrastructure risk
Brand Protection (BP) Phishing sites, dark web mentions, leaked credentials, scams — brand abuse
General Detection Unclassified detections awaiting triage

Module Weights

Weights control how much each module affects the overall score. Weights must add up to 100%.

Example:

  • ASM: 40% — infrastructure risk has the biggest influence
  • BP: 35% — brand abuse is a close second
  • Detection: 25% — unclassified items matter less

If a customer's primary concern is brand abuse, you'd increase BP's weight and decrease the others.


Editing a Module

Click a module row to open the Module Editor side panel where you can:

  • Change the module name and description
  • Adjust the weight
  • Enable or disable the module
  • Link a different formula

After saving, the next scoring run will use the updated settings.


Adding a Module

Click the "Add Module" button above the table to create a new module definition. This is typically done during initial setup and is rare after that.

Note: Modules are usually auto-created when scoring runs for the first time. You'll rarely need to add one manually.