It may be defined by different ways by each technology. But the main thing is:
Alerts: Individual alerts provides a valuable clue of an ongoing attack.
Incidents: Incident are comprised with multiple alerts or you can say multiple alerts are grouped together to form an incident to make up the story of the attack.
Comments
Post a Comment