Skip to main content
Version: Spectra Detect 6.4.0

Spectra Detect Risk Tolerance Levels — Classification Override Settings

Risk Tolerance Levels let you override a sample's final classification, based on how confident the verdict is and whether network threat intelligence found a malicious indicator. The setting is global, which means it applies to every appliance and configuration group connected to this Spectra Detect Manager, with no per-group override.

tip

Risk Tolerance Levels can also be set up in Spectra Analyze. Spectra Detect's version overrides based on the Worker's own classification confidence and network threat intelligence, since Spectra Detect doesn't run the additional analysis sources (Cloud Sandbox, Joe Sandbox, configurable YARA rulesets) that Spectra Analyze does.

If a file is analyzed by both products, each applies its own Risk Tolerance level and neither takes precedence — these are separate analyses that can reach different classifications. Risk Tolerance is only one reason the results can differ: processing settings (best, fast), the decompression factor, ML model configuration and other factors also influence the outcome.

For more context on how classification and risk factors work together, see the Classification guide.

Risk tolerance levels comparison​

HighReversingLabs DefaultLow
Best forEnvironments that minimize noise and act only on the highest-risk threats.Standard deployments that require unmodified engine verdicts.High-security environments where network-based indicators of compromise are treated as critical threats.
Threat verdictSamples classified as Suspicious, or Malicious with an RCA2 factor of 6 or below, are overridden to Goodware with an RCA2 factor of 5.No override is applied. The top-level verdict follows the standard engine evaluation.The top-level container classification is elevated to Malicious with an RCA2 factor of 6 when a malicious network indicator of compromise (IOC) is found.
Network threat intelligenceDoesn't impact final classification.Doesn't impact final classification.Findings are included in the classification decision.
Report outputAdds a top-level administrative override scanner entry with the reason "high threat level tolerance - ignoring all low threat levels". Previous low-threat scan results are marked as ignored.Report remains unchanged from the standard engine evaluation.Adds a top-level administrative override scanner entry with the reason "overriding to malicious due to malicious network IOCs found".

Selecting a risk tolerance level​

Only Superuser accounts can see and change the Risk Tolerance setting.

  1. Click Risk Tolerance in the Spectra Detect Manager header. The button shows the currently active level.
  2. In the Risk Tolerance Levels dialog, review the available levels and their effects.
  3. Click the desired level to select it.
  4. Click Apply Changes to save the selection, or Cancel to close the dialog without changes.

The active level is indicated with a green checkmark and the (Active) label.

warning
  • Choosing High reduces the number of alerts you receive, but may also cause genuinely malicious low-confidence samples to be classified as Goodware. Choosing Low increases detection of network-based threats, but may also increase false positives from network indicators alone.
  • Global and advanced filters use a sample's final, post-override classification to pass or drop files.