Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is a security alert?

A security alert is a notification that a product, rule or analyst has found activity worth looking at.

It is useful because it points you towards which account, device, file, connection or period deserves attention.

It is not the same thing as a source record and it is not automatically proof that an attack succeeded.

An alert sits on top of other events

A simple relationship looks like this:

Source eventsWhat did the systems record?Authentication, process, file, network or configuration activity.
Detection logicWhy was it considered interesting?Rule, model, threshold or intelligence match.
AlertWhat was surfaced?Label, severity, affected object and time.

The alert helps you navigate to the source evidence.

Read the alert for what it can give you

Useful alert fields may include:

  • alert ID;
  • rule or detection name;
  • account;
  • host/device;
  • file or process;
  • source/destination address;
  • severity;
  • confidence;
  • timestamp;
  • linked source events;
  • analyst comments.

A simplified alert might show:

Example security alert
alert_id=AL-88021rule=Suspicious PowerShellhost=ADMIN-07user=nv-supportseverity=hightriggered=2026-09-14 05:37:58 UTC

That is enough to tell you where to look next.

Product labels need testing

Words such as “malicious”, “compromised” or “credential theft” may be detection labels.

They can be accurate, but you still need to understand:

  • what triggered the label;
  • whether the action was blocked;
  • whether it completed;
  • what source events support it.

Does a security alert prove an attack happened? deals with that directly.

Preserve the alert and the route beneath it

Keep the alert because it records what the security system saw and when.

Also preserve:

  • the underlying source events;
  • the rule/version where relevant;
  • any later analyst triage;
  • reclassification;
  • containment actions.

That lets another investigator understand both the technical activity and why it was treated as suspicious.

The practical point is: use an alert as a signpost. It tells you where to investigate; the source events tell you what actually happened.

Reference: CIM-015Cyber Incidents & Offender Methods