Peer Groups

Peer groups are logical collections of entities, identities and assets, that share common characteristics, permissions, or organizational attributes.

In Anomali Agentic SOC Operations, peer groups serve two purposes:

  • Organizational Context: Each group carries a Risk Score Multiplier that contributes to the weighted average peer group modifier applied during risk calculation for all member entities. Assigning appropriate multipliers allows your team to encode organizational context directly into the scoring engine: a detection for a privileged administrator carries materially different risk weight than the same detection for a read-only service account. See Entity Risk Scores for details on how multipliers factor into the formula.

  • Risk Comparison: Peer groups provide a basis for comparison in the Risk Score tab of each entity detail page, allowing administrators to plot an entity risk score against its peers in the group and, therefore, better understand whether an elevated entity score reflects a genuine outlier or a pattern shared across the group.

Group Types

Anomali Agentic SOC Operations supports two group types:

  • IDP-sourced groups: Synchronized from an external identity or asset management system, for example, Active Directory, Okta, or a CMDB. Membership is managed at the source and is read-only within the platform. Administrators can configure the Risk Score Multiplier for any IDP-sourced group.

  • Custom groups: Created and managed directly within Anomali Agentic SOC Operations. Both the membership and the Risk Score Multiplier are fully configurable. Custom groups are visually distinguished with a Custom badge in all list and detail views. See Creating Custom Peer Groups for more information.

Group Hierarchy

Peer groups support parent-child relationships. Hierarchies are visible in the Peer Group list panel, where child groups are indented beneath their parent and can be expanded or collapsed. Additionally, custom groups can be configured as subgroups of both custom and IDP-sourced groups.

Risk Score Multiplier

Every group has a Risk Score Multiplier with a range of 0.1 to 2.0 and a default value of 1.0 (neutral). Values above 1.0 increase the risk contribution of detections for all member entities, whereas values below 1.0 reduce it. When an entity belongs to multiple groups, the system calculates the weighted arithmetic mean of all applicable group multipliers as the peer group modifier for that entity.

Multiplier changes take effect on the next risk calculation cycle for all member entities, so all member entities will have their scores recomputed using the updated multiplier on the next cycle based on the updated risk calculation. All changes are recorded in the audit log with the previous value, new value, timestamp, and administrator identity.

Accessing Peer Groups

To access Peer Groups, on the left navigation bar, click Peer Groups. See Understanding Peer Groups for a detailed description of the interface.

Permissions

Access to peer groups is governed by the same two permissions that apply to all entity management. There is no per-group sharing, that is, a permission grants access to all peer groups in the organization, or none of them.

Action Permission Required
View peer groups and group membership View Entities
Set or change a Risk Score Multiplier Manage Entities
Create a custom peer group
Edit or delete a custom peer group
Add or remove entities from a custom group

For details on assigning these permissions to a role, see Managing Roles.