📊
Understanding Alert Severity Levels
A comprehensive guide to understanding and responding to security alerts based on their severity level.
Alert Severity Levels
| Level | Meaning | Response | Example |
|---|---|---|---|
| 🔴 CRITICAL | Active attack in progress | Immediate | Ransomware, C2, data breach |
| 🟠 HIGH | Suspicious activity detected | Within 1 hour | Brute force, privilege escalation |
| 🟡 MEDIUM | Unusual, not immediately threatening | Within 4 hours | New user, system warning |
| 🔵 LOW | Minor anomalies detected | Within 24 hours | Config changes, metrics |
📋 Response Protocol
🔴 CRITICAL
- Check alert immediately
- Ask AI for analysis
- Isolate if confirmed
- Auto-block enabled
🟠 HIGH
- Review within 1 hour
- Investigate source IP
- Ask AI for context
- Block if malicious
🟡 MEDIUM
- Review within 4 hours
- Check if expected
- Mark false positive if needed
🔵 LOW
- Review during regular checks
- Use for trend analysis
- No immediate action needed