Attack Scenarios (< v. 3.36)
You define an attack scenario by selecting the types of attack for Tenable Identity Exposure to monitor on specific domains.
Workload Quota
Each Indicator of Attack in Tenable Identity Exposure has an associated workload quota that takes into account the resources required to analyze data from an attack.
Tenable Identity Exposure calculates the workload quota to limit the number of Indicators of Attack (IoAs) running simultaneously which has an impact on bandwidth and CPU usage for event generation on domain controllers.
After you modify the workload quota limit, do the following:
-
Increase: Monitor statistics following the increase to ensure a comfortable margin.
-
Decrease: Deactivate some IoAs to stay under this quota, which reduces security coverage against attacks.