Help topic · 2 common questions

Security incidents

Move from alert confirmation to mitigation and review with a clear, traceable incident process.

01What should I do first after an attack alert?

Confirm the affected domain, time range and user impact before broadening a blocking rule. Keep the alert ID and contact on-call support.

  1. Check user and origin impact
  2. Record the alert time, peak and attack type
  3. Share the alert ID with support
02When does a blocking rule take effect?

Published rules propagate quickly to edge locations. For a high-risk rule, start in observe or challenge mode, then move to block after checking false positives.

1DUN SUPPORT

Under attack and need immediate help?

Share your context and what you are seeing. Our support team will help with the next step.

Contact support
Did this answer your question?