Terminology Index
Glossary
1801 terms
Showing 1089-1120 of 1801 terms
Network Alerts
SOC alerts generated from network-level signals, IDS/IPS hits, suspicious connections, DNS anomalies, that analysts triage to find network-based attacks like command-and-control, scanning, and exfiltration.
Network alerts are produced by network monitoring, IDS/IPS systems, NDR tools, DNS analytics, and SIEM rules, flagging activity like communication with known-malicious infrastructure, beaconing, scanning, or data exfiltration. Analysts triage them with context (which host, which user, what flows), separating benign quirks from real threats. They complement endpoint and identity alerts, and effectively triaging them requires understanding networking fundamentals and the kinds of attacks network signals reveal.
Introduced in: SOC Analyst Fundamentals
Examples
- Triaging an IDS hit that flagged traffic to known-malicious infrastructure.
- Investigating an alert on suspicious beaconing from a host.
- Following up on a DNS anomaly that may indicate exfiltration.
No related terms linked yet.
