Observables is not something to score. It is observed, or it is not.
To assess if an Observable is associated with malicious practices, the Indicator Object must be used.
CTI sources provide Indicator with a "relevance" score.
Detection systems provides Observables that have been seen in logs
Observables matches Indicators' pattern
To implement:
removing score from Observable schema and views.
Use case
Observables is not something to score. It is observed, or it is not. To assess if an Observable is associated with malicious practices, the Indicator Object must be used.
CTI sources provide Indicator with a "relevance" score. Detection systems provides Observables that have been seen in logs Observables matches Indicators' pattern
To implement: removing score from Observable schema and views.