Alert
Definition
A notification generated when an event or pattern of events matches a detection rule. Alerts require triage to determine whether they represent genuine threats; many alerts are false positives.
- Trigger
- Event or pattern matching a detection rule
- Requires
- Triage to confirm genuine threat
- Common issue
- High volume of false positives
Common questions
Why do detection systems generate so many false-positive alerts?+
Detection rules are often written broadly to avoid missing genuine attacks, which trades precision for recall, so legitimate but unusual user or system behaviour frequently matches the same pattern as malicious activity and gets flagged.
What happens to an alert that is not properly triaged?+
It can be dismissed or left unreviewed alongside genuine noise, and in several documented breaches, an early alert that indicated the actual intrusion was buried among false positives and only recognised in hindsight during the post-incident investigation.
Related terms
- Data Breach
- An incident in which an unauthorised party gains access to, copies, or discloses protected data. Breaches trigger specific legal notification requirements under...
- Insider Threat
- An incident originating from a person with legitimate access to an organisation's systems, whether through malicious intent (data theft, sabotage) or negligence...
- Ransomware
- Malware that encrypts or exfiltrates data and demands payment for restoration or suppression. Modern ransomware incidents often combine an availability impact (encrypted...
- Security Event
- Any observable occurrence in a system or network. Events are the raw material from which alerts and incidents are identified; the vast...
- Security Incident
- An event or chain of events that violates an organisation's security policy or credibly threatens the confidentiality, integrity, or availability of information...