On this page:
Related topics:
Peer Groups
Peer groups are logical collections of entities, identities and assets, that share common characteristics, permissions, or organizational attributes.
In Anomali Agentic SOC Operations, peer groups serve two purposes:
-
Organizational Context: Each group carries a Risk Score Multiplier that contributes to the weighted average peer group modifier applied during risk calculation for all member entities. Assigning appropriate multipliers allows your team to encode organizational context directly into the scoring engine: a detection for a privileged administrator carries materially different risk weight than the same detection for a read-only service account. See Entity Risk Scores for details on how multipliers factor into the formula.
-
Risk Comparison: Peer groups provide a basis for comparison in the Risk Score tab of each entity detail page, allowing administrators to plot an entity risk score against its peers in the group and, therefore, better understand whether an elevated entity score reflects a genuine outlier or a pattern shared across the group.
Group Types
Anomali Agentic SOC Operations supports two group types:
-
IDP-sourced groups: Synchronized from an external identity or asset management system, for example, Active Directory, Okta, or a CMDB. Membership is managed at the source and is read-only within the platform. Administrators can configure the Risk Score Multiplier for any IDP-sourced group.
-
Custom groups: Created and managed directly within Anomali Agentic SOC Operations. Both the membership and the Risk Score Multiplier are fully configurable. Custom groups are visually distinguished with a Custom badge in all list and detail views. See Creating Custom Peer Groups for more information.
Group Hierarchy
Peer groups support parent-child relationships. Hierarchies are visible in the Peer Group list panel, where child groups are indented beneath their parent and can be expanded or collapsed. Additionally, custom groups can be configured as subgroups of both custom and IDP-sourced groups.
Risk Score Multiplier
Every group has a Risk Score Multiplier with a range of 0.1 to 2.0 and a default value of 1.0 (neutral). Values above 1.0 increase the risk contribution of detections for all member entities, whereas values below 1.0 reduce it. When an entity belongs to multiple groups, the system calculates the weighted arithmetic mean of all applicable group multipliers as the peer group modifier for that entity.
Multiplier changes take effect on the next risk calculation cycle for all member entities, so all member entities will have their scores recomputed using the updated multiplier on the next cycle based on the updated risk calculation. All changes are recorded in the audit log with the previous value, new value, timestamp, and administrator identity.
Accessing Peer Groups
To access Peer Groups, on the left navigation bar, click Peer Groups. See Understanding Peer Groups for a detailed description of the interface.
Permissions
Access to peer groups is governed by the same two permissions that apply to all entity management. There is no per-group sharing, that is, a permission grants access to all peer groups in the organization, or none of them.
| Action | Permission Required |
|---|---|
| View peer groups and group membership | View Entities |
| Set or change a Risk Score Multiplier | Manage Entities |
| Create a custom peer group | |
| Edit or delete a custom peer group | |
| Add or remove entities from a custom group |
For details on assigning these permissions to a role, see Managing Roles.