Intelligence
Intelligence
When data triggers an indicator, an alert is created. The alert is an entry in the Perch console. Each alert contains the data and/or metadata of the packet/payload that triggered the rule. When an alert is generated it also triggers a siren to go off in our SOC pit, causing widespread panic and mayhem, followed by investigation and escalation if necessary.
Your latest 5 alerts are seen right from the dashboard (if you have any), or you can view alerts from the alert dashboard by navigating to Threats->Alerts from the main menu.
On the alert dashboard alerts are grouped by indicator.
The above is an example of an alert as seen in the app. Let’s break it down: