Multiple modify.conf files (but named differently) + increase in severity

The free version of IDSTower (demo link) can attain the same results you are trying to achieve:-

  1. you can group the rules that are in CISA list by either adding them to a category or adding a tag to them (both are exported as metadata in the generated alerts and can be filtered on).
  2. you can override the the priority/severity level of the rules in this category without having to alter the source code (IDSTower will do it for you), which again is exported in the generated alerts and can be used to prioritize the triage process.