Risk-Based Alerting (RBA) fundamentally changes SIEM alerting. Instead of creating a Notable Event directly, a Risk Rule creates a Risk Modifier.
The modifier assigns a numerical score (e.g., +20) to a Risk Object (a user or system) based on a low-fidelity event (like an encoded PowerShell command).