📊 Understanding Alert Severity Levels
| Level | Meaning | Response | Example |
|---|---|---|---|
| 🔴 CRITICAL | Active attack in progress | Immediate | Ransomware, C2, data breach |
| 🟠HIGH | Suspicious activity | Within 1 hour | Brute force, privilege escalation |
| 🟡 MEDIUM | Unusual, not threatening | Within 4 hours | New user, system warning |
| 🔵 LOW | Minor anomalies | Within 24 hours | Config changes, metrics |
Response Protocol
CRITICAL:
1. Check alert immediately
2. Ask AI for analysis
3. Isolate if confirmed
4. Auto-block enabled
1. Check alert immediately
2. Ask AI for analysis
3. Isolate if confirmed
4. Auto-block enabled
HIGH:
1. Review within 1 hour
2. Investigate source IP
3. Ask AI for context
4. Block if malicious
1. Review within 1 hour
2. Investigate source IP
3. Ask AI for context
4. Block if malicious
MEDIUM:
1. Review within 4 hours
2. Check if expected
3. Mark false positive if needed
1. Review within 4 hours
2. Check if expected
3. Mark false positive if needed
LOW:
1. Review during regular checks
2. Use for trend analysis
3. No immediate action needed
1. Review during regular checks
2. Use for trend analysis
3. No immediate action needed