Major Category of Alarm | Alarm Type | Alarm Item | Alert Range | Message Center/SMS/Mail, Etc | Robot Notification |
| | | | Alarm Time | Alarm Time |
Intrusion detection | Virus scanning | Serious, High risk, Medium risk, Low risk, Note. | All/Custom | All-day/Custom Note: To reduce disturbance to users, Alarms have the following restrictions: At the start of the alarm time period, receive real-time notifications for the first 3 security alarms, followed by a summary notification every 2 hours. Alarms generated during the non-alarm time period will be summarized and notified at the start of the alarm time. | real-time |
| Virus Scanning - abnormal process | An abnormal process running in memory has been detected. | | | |
| Unusual login | High risk, Suspicious. | | | |
| Password cracking | The login password has been successfully cracked. | | | |
| Malicious request | The server requested a malicious domain name. | | | |
| High-risk command | High risk, Medium risk, Low risk. | | | |
| Local privilege escalation | Low privilege attempting to elevate in the system. | | | |
| Reverse Shell | A Shell reverse connection occurs on servers. | | | |
Vulnerability management | Urgent vulnerability | Serious, High risk, Medium risk, Low risk. | | | |
| Linux software vulnerability | Serious, High risk, Medium risk, Low risk. | | | |
| Windows system vulnerability | Serious, High risk, Medium risk, Low risk. | | | |
| Web-CMS vulnerability | Serious, High risk, Medium risk, Low risk. | | | |
| Application vulnerability | Serious, High risk, Medium risk, Low risk. | | | |
| Vulnerability defense | Successfully defended vulnerability exploitation attack event. | | | |
Baseline management | Security Baseline | Exist baseline items that fail detection (account-related, weak password, unauthorized access baselines). | | | |
Cyber Defense | Network attack | Successful attack, attempted attack. | | | |
| Java Webshell | A Java Webshell has been detected in the JavaWeb Service Process. | | | |
| Core file monitoring | High risk, Medium risk, Low risk, None. | | | |
Client-related | Client offline | Client abnormal offline has been detected and it has not been back online within a specified period. | | | |
| Client uninstallation | Client uninstalled has been detected. | | | |
Log Analysis | Log analysis storage | When the log storage volume reaches a certain percentage, a log storage alarm will be triggered. | Not involved | real-time | |
News-related | Security Broadcast | Security announcement Version release Feature updates Practice Industry honor | | | |