Skip to main content
Version: Spectra Analyze 9.12.0

Risk Tolerance Levels

Spectra Analyze > Administration > Users & Personalization > Risk Tolerance Levels

Risk tolerance levels determine how aggressively Spectra Analyze classifies samples by configuring which analysis sources contribute to the final classification. Spectra Analyze provides multiple risk tolerance levels, each with different analysis sources and thresholds. For more context on how classification and risk factors work together, see the Classification guide.

info
  • The availability of analysis sources depends on your appliance configuration.
  • RL Cloud Sandbox results are weighed more heavily and can classify a sample as malicious even if other sources do not.
warning

Higher sensitivity levels include more sources and lower thresholds, which increases detection rates but may also increase false positives.

Default risk tolerance level​

ReversingLabs Default is the default configuration that provides balanced detection without additional analysis sources. In this case, only RL Cloud Sandbox can change the final classification from Suspicious to Malicious.

Risk tolerance levels comparison​

Analysis SourceReversingLabs DefaultHighMediumLow
Auxiliary AnalysisNo impactScore >1000: Malicious
Score >700: Suspicious
Score >700: Malicious
Score >300: Suspicious
Score >700: Malicious
Score >300: Suspicious
Network DataNo impactApply payload classification to URL.Apply payload classification to URL and consult at least two 3rd party reputation sources.Apply payload classification to URL and consult at least one 3rd party reputation source.
RL Cloud SandboxCan change Suspicious to Malicious (setting can be enabled on integration page).Score >7: Malicious
Score >5: Suspicious
Score >5: Malicious
Score >3: Suspicious
Score >5: Malicious
Score >3: Suspicious
Joe SandboxNo impactMalicious/Suspicious detection with confidence == 5 (fixed risk factor: 5)Malicious/Suspicious detection with confidence ≥ 4 (fixed risk factor: 5)Malicious/Suspicious detection with confidence ≥ 4 (fixed risk factor: 5)
YARANo impactYARA Forge Core RulesetYARA Forge Extended RulesetYARA Forge Full Ruleset
note

Joe Sandbox classification no longer uses Joe's calculated malicious score. Instead, a sample is classified as Malicious or Suspicious based on Joe Sandbox's own detection verdict combined with a minimum confidence level, and, when triggered, is assigned a fixed risk factor of 5 regardless of malware type or threat level.

Selecting a risk tolerance level​

To select a risk tolerance level:

  1. Go to Administration > Users & Personalization > Risk Tolerance Levels.
  2. Review the available risk tolerance levels and their respective settings.
  3. Click the desired risk tolerance level to select it.
  4. Click Apply changes to save the selection, or Discard to cancel.

The active risk tolerance level is indicated with an (Active) label.

Configuring a risk tolerance level​

To configure a risk tolerance level:

  1. Go to Administration > Users & Personalization > Risk Tolerance Levels.
  2. Click Configure on the desired risk tolerance level to expand the configuration options.
  3. Select or clear the checkboxes next to each analysis source to enable or disable them:
    • Auxiliary Analysis
    • Network Data
    • RL Cloud Sandbox
    • Joe Sandbox
    • YARA
  4. Click Apply changes to save the configuration, or Discard to cancel.