What is ZTRS?
ZTRS (Zero Trust Risk Score) is TripleCyber's proprietary risk scoring engine. It assigns a continuous, real-time risk score to every user, device, and session in your environment. ZTRS combines external threat intelligence from IPQS (IP Quality Score) with internal behavioral data from TripleSOC to produce a score that reflects current risk, not historical trust.
How It Fits into TripleSOC
ZTRS is the risk intelligence layer that powers trust decisions across the entire TripleSOC platform:
- Trust zone transitions — ZTRS scores determine when an entity moves between Anonymous, Verified, and Secure zones
- Alert prioritization — TripleSOC uses ZTRS scores to rank alerts by actual risk, reducing noise and surfacing critical threats first
- Automated response triggers — when a ZTRS score crosses a defined threshold, TripleSOC can automatically isolate endpoints, revoke certificates, or restrict access
Key Capabilities
- Continuous scoring — risk scores update in real time as new data arrives, not on a periodic schedule
- IPQS integration — consumes IP reputation, email verification, phone validation, and device fingerprint data from IPQS
- Behavioral analysis — factors in login patterns, access anomalies, and network behavior from TripleSOC telemetry
- Configurable thresholds — administrators define risk score boundaries for trust zone transitions and automated actions
- Transparent scoring — every score includes a breakdown of contributing factors visible in the TripleSOC dashboard
How It Works with Other Components
ZTRS scores feed directly into Triple ABAC policy decisions. When a user's risk score rises, ABAC policies automatically restrict access without manual intervention. Triple OAuth uses ZTRS to trigger step-up authentication. Triple DNS uses ZTRS to restrict domain resolution for high-risk entities. Triple PKI uses ZTRS to flag certificates for re-evaluation when the associated device's risk posture degrades.