What is a security alert?¶
A security alert is a notification that a product, rule or analyst has found activity worth looking at.
It is useful because it points you towards which account, device, file, connection or period deserves attention.
It is not the same thing as a source record and it is not automatically proof that an attack succeeded.
An alert sits on top of other events¶
A simple relationship looks like this:
The alert helps you navigate to the source evidence.
Read the alert for what it can give you¶
Useful alert fields may include:
- alert ID;
- rule or detection name;
- account;
- host/device;
- file or process;
- source/destination address;
- severity;
- confidence;
- timestamp;
- linked source events;
- analyst comments.
A simplified alert might show:
That is enough to tell you where to look next.
Product labels need testing¶
Words such as “malicious”, “compromised” or “credential theft” may be detection labels.
They can be accurate, but you still need to understand:
- what triggered the label;
- whether the action was blocked;
- whether it completed;
- what source events support it.
Does a security alert prove an attack happened? deals with that directly.
Preserve the alert and the route beneath it¶
Keep the alert because it records what the security system saw and when.
Also preserve:
- the underlying source events;
- the rule/version where relevant;
- any later analyst triage;
- reclassification;
- containment actions.
That lets another investigator understand both the technical activity and why it was treated as suspicious.
The practical point is: use an alert as a signpost. It tells you where to investigate; the source events tell you what actually happened.