Security incidents
Move from alert confirmation to mitigation and review with a clear, traceable incident process.
01What should I do first after an attack alert?
Confirm the affected domain, time range and user impact before broadening a blocking rule. Keep the alert ID and contact on-call support.
- Check user and origin impact
- Record the alert time, peak and attack type
- Share the alert ID with support
02When does a blocking rule take effect?
Published rules propagate quickly to edge locations. For a high-risk rule, start in observe or challenge mode, then move to block after checking false positives.
1DUN SUPPORT
Contact supportUnder attack and need immediate help?
Share your context and what you are seeing. Our support team will help with the next step.
Did this answer your question?