What is an alert?¶
An alert is a notification generated when a system, rule or analyst identifies activity considered noteworthy.
Avoid this assumption: That an alert proves that malicious or unauthorised activity occurred. An alert normally shows that defined conditions were met, not that the final interpretation is correct. Alerts may be generated by antivirus software, endpoint detection tools, firewalls, identity systems, cloud platforms, fraud systems or a security information and event management platform. They may be based on a single event, several correlated events, a threshold, a known signature, unusual behaviour or a calculated risk score.
The quality of an alert depends on the data available and the rule used. If source logs were missing, delayed or incorrectly parsed, the alert may be incomplete or misleading. A rule may also generate false positives where legitimate activity matches suspicious criteria, or false negatives where relevant activity is not detected.
An alert may include severity, confidence, affected account, device, IP address, rule name, detection time and analyst disposition. These fields require careful interpretation. High severity may reflect potential impact rather than proof. Detection time may be later than event time. An analyst closure may record a workflow decision, not a definitive evidential finding.
Investigators should preserve the alert and request the underlying source events, the detection rule, rule version, relevant thresholds, field definitions and any analyst notes. Check whether the alert was updated after creation and whether several alerts relate to the same underlying activity.
An alert can be a valuable lead. It may identify activity requiring preservation, corroboration or urgent action. It should not be presented as standalone proof of the offence, the offender’s identity or malicious intent.
Where the alert will support significant operational or evidential decisions, seek explanation from the system owner or an appropriate specialist.
Operational takeaway¶
Use an alert as a prompt to examine the underlying evidence, not as a substitute for that evidence.