Skip to main content
Per-product triage for the tools in your stack — what an alert from each vendor means and what to do about it.

1Password Business

Run 1Password Business admin work: vault and group structure, sharing discipline, the Emergency Kit, recovery groups, and suspend-then-recover offboarding.

Abnormal Security

Triage Abnormal Security email cases: read ATO and BEC behavioral signals, treat account takeover as an identity incident, finish auto-remediation gaps.

Acronis Cyber Protect

Handle Acronis Cyber Protect alerts: separate a backup failure from an Active Protection anti-ransomware detection and run the matching triage discipline.

APC UPS Alerts

Work APC UPS alerts: on-battery events, low runtime, self-test failure, or replace-battery indicators. Separate utility issues from UPS hardware faults.

Arctic Wolf MDR

Work Arctic Wolf MDR escalations: pick up where their SOC investigation ended and split response authority between Arctic Wolf and the MSP correctly.

Auvik Network Monitoring

Triage Auvik network alerts: separate device-down, interface-down, and config-change events, and use the topology map to spot cascades early.

Axcient Backup Alerts

Triage Axcient x360Recover alerts: distinguish appliance vs Direct-to-Cloud failure families, verify retention, and state the last recoverable point.

Bitdefender GravityZone

Triage Bitdefender GravityZone alerts: identify the detection layer (AV, ATC, HyperDetect, EDR) and use Risk Analytics, quarantine, and rollback safely.

Bitwarden Business

Run Bitwarden Teams/Enterprise admin work: organization and collection structure, group-based sharing, account recovery, and offboarding vault handover.

Blackpoint SOC Response

Work Blackpoint MDR SOC calls: confirm what analysts contained (host isolation, account disable), finish the response, and merge companion ticket storms.

Cork Protection Posture

Handle Cork cyber-warranty posture signals: identify the required control that slipped and restore it to compliance before warranty coverage lapses.

Cove Data Protection Alerts

Work N-able Cove Data Protection backup tickets: classify the failure family, verify recoverability, and keep archive and retention sessions straight.

CrowdStrike Falcon Alerts

Triage CrowdStrike Falcon detections: parse detection anatomy, decide when Network Contain is warranted, and spot mass endpoint failures as vendor-side.

Datto BCDR Verification

Work Datto BCDR alerts: screenshot-verification failures, local vs cloud sync lag, virtualization tests. Separate backup-ran from backup-boots and verify.

Defender M365 Alerts

Triage Microsoft Defender and Entra alerts: Safe Links or Safe Attachments detonation, suspicious inbox rules, risky sign-in. Correlate to the incident.

Defender Quarantine Ops

Review Microsoft 365 Defender quarantine items and release requests using Defender portal paths, verdict types, and disciplined release mechanics.

DNS Filtering Alerts

Handle DNS-filter block events from Cisco Umbrella, DNSFilter, and similar tools: separate security blocks from category blocks, keep bypass discipline.

Duo MFA Anomalies

Work Duo MFA events: fraudulent pushes, push-fatigue patterns, device re-enrollment, bypass codes. Verify identity and time-box every bypass grant.

ESET PROTECT

Triage ESET PROTECT detections by engine, interpret LiveGuard sandbox verdicts, and recognize when a protection-disabled alert is really a policy conflict.

Huntress EDR Incident

Work Huntress EDR incident reports: foothold, persistence, or active endpoint threats. Read what Huntress isolated, finish remediation, and verify closure.

Huntress ITDR Alerts

Work Huntress ITDR identity reports: unwanted access, rogue apps, mail-rule anomalies. Verify with the user and drive the remediation-approval flow closed.

IRONSCALES Phishing

Work IRONSCALES phishing incidents and user banner reports: mailbox-level detection, automated remediation, and correct model-training feedback.

Kaseya Dark Web Monitoring

Work Kaseya Dark Web ID compromise alerts: parse alert anatomy (source, date, data classes) and run the age-and-notify lifecycle with a no-crack policy.

Keeper Password Manager

Run Keeper Security admin work: vault and shared-folder structure, role-enforced sharing, break-glass access, and offboarding via Account Transfer.

KnowBe4 Awareness & PhishER

Run a KnowBe4 program: awareness training, phishing simulations, and triage user reports through PhishER and the Phish Alert Button without collisions.

LastPass Migration

Run a LastPass migration-away: export, import to a new vault, rotate every secret, decommission the account, and handle the breach-history talk with facts.

M365 SaaS Backup

Work M365 and Google Workspace SaaS backup tickets: point-in-time restores, license and seat reconciliation, and job failures with authorization checks.

Mimecast Email Gateway

Work Mimecast gateway events: held-message release requests, URL Protect click alerts, and impersonation-protect hits. Treat allowed clicks as incidents.

NinjaOne Alert Types

Classify NinjaOne condition and threshold alerts (offline, resource, service, patch, hardware, security) and route each class with a deep-link handoff.

Proofpoint Email Security

Work Proofpoint email security events: TAP click alerts, attachment-sandbox verdicts, quarantine-digest release requests, and VAP-driven priority triage.

SaaS Alerts MDR

Triage SaaS Alerts events in M365 and Google tenants: login anomalies, mail-rule creation, file-activity spikes, privilege changes as identity-plane EDR.

ScreenConnect Access

Troubleshoot ScreenConnect / ConnectWise Control access: unattended-agent health, session connectivity, and console handoff for the technician on duty.

Security Vendor Generic

Handle security alerts from any vendor without a dedicated runbook: extract alert anatomy, map severity to desk tiers, build a vendor escalation package.

SentinelOne Ranger

Work SentinelOne Ranger network-discovery findings: read the rogue or unmanaged-device signal and drive to identify-then-manage without blind action.

SentinelOne Threat Verdict

Triage SentinelOne threat detections: read static vs behavioral engine verdicts, direct kill, quarantine, rollback, and hold on exclusion requests.

Sophos Endpoint Alerts

Triage Sophos Central endpoint alerts: read health status and cleanup result, handle tamper protection correctly, and verify cleanup before closing.

Synology NAS Alerts

Work Synology NAS alerts: degraded RAID or storage pool, disk-health warnings, full volumes, DSM updates. Treat a degraded array as near data loss.

TeamViewer Access

Troubleshoot TeamViewer remote access: host and agent health, unattended access, session connectivity, and the commercial-use-detected flag on handoff.

ThreatDown Malwarebytes

Triage ThreatDown (Malwarebytes) detections by class — malware, PUP, PUM, exploit — and run the remediation-verification pass the remediated status skips.

ThreatLocker Allowlisting

Work ThreatLocker approval and elevation requests: triage daily allowlisting safely, keep Learning vs Secured mode straight, protect zero-trust posture.

Todyl Platform

Route Todyl alerts by plane: SASE network, endpoint EDR, or identity and SIEM detection. Each plane needs a different runbook from the same platform.

Trend Micro Worry-Free

Triage Trend Micro Worry-Free alerts by engine (signature, ML, behavior, web reputation) and know when a client is on Apex Central or Vision One instead.

Veeam Job Failures

Diagnose Veeam backup job failures: classify by taxonomy (VSS, credentials, repository, network), apply retry discipline, and state the last restore point.

WatchGuard Firewall Alerts

Triage WatchGuard events: Firebox offline in WatchGuard Cloud, AuthPoint MFA push and token trouble, and mobile VPN authentication failures on the desk.

Webroot Legacy AV

Work Webroot or other legacy signature-AV detections with thin telemetry, and frame the modern-EDR migration conversation on facts, not fear.