← KB

📊 Understanding Alert Severity Levels

LevelMeaningResponseExample
🔴 CRITICALActive attack in progressImmediateRansomware, C2, data breach
🟠 HIGHSuspicious activityWithin 1 hourBrute force, privilege escalation
🟡 MEDIUMUnusual, not threateningWithin 4 hoursNew user, system warning
🔵 LOWMinor anomaliesWithin 24 hoursConfig changes, metrics

Response Protocol

CRITICAL:
1. Check alert immediately
2. Ask AI for analysis
3. Isolate if confirmed
4. Auto-block enabled
HIGH:
1. Review within 1 hour
2. Investigate source IP
3. Ask AI for context
4. Block if malicious
MEDIUM:
1. Review within 4 hours
2. Check if expected
3. Mark false positive if needed
LOW:
1. Review during regular checks
2. Use for trend analysis
3. No immediate action needed