Score events according to their randomness based on the Shannon entropy of the string value of the specified column. Higher scores are given to more random strings. If a string contains no duplicate characters, it gets the highest score. Strings with duplicate characters get lower scores.
- Click + on the parent node.
- Enter the Score by Randomness operator in the search field and select the operator from the Results to open the operator form.
- In the Input Table drop-down, enter or select the name of the table containing the data to run this operator on.
- In the Column drop-down, enter or select a column from which the score will be computed.
- Click Run to view the result.
- Click Save to add the operator to the playbook.
- Click Cancel to discard the operator form.
column: Column name to compute randomness score.
table: Name of a table.
The input table with an additional lhub_score column containing the score. The score reflects the randomness (Shannon) of a string.
Updated almost 3 years ago