Skip to content
Skip to main content
Logs, Records & Provider Evidence Technical Explainer

Does a high-severity alert prove malicious activity?

No. Severity ordinarily expresses priority, potential impact or urgency. It is a property of the alerting process, not confirmation that hostile activity occurred or succeeded.

Severity can reflect different dimensions

A vendor rule, local configuration, risk score, analyst or asset value may assign the label. The same detection can be rated higher on a critical server than on a test device. Some products combine likelihood and impact; others use only one.

Early-warning systems deliberately tolerate false alerts where missing a serious event would be costly. A blocked attempt may therefore be rated highly despite causing no compromise.

Establish what the label meant in that system

Preserve the severity, assignment source, rule and later changes. Determine whether it reflected likelihood, confidence, impact or response priority, then examine the underlying events and technical outcome.

Keep the original label in the record, but report it as the platform's prioritisation. Whether activity was attempted, blocked, partly completed or successful must be supported by source and consequence evidence.

The point to remember

High severity calls for attention; it does not substitute for evidence of maliciousness or outcome.

Reference: LOG-108Logs, Records & Provider Evidence