alerts

Alert Management

Never miss a
critical threat.

Multi-channel alerting with intelligent routing, severity escalation and noise reduction — so your team responds to what actually matters.

3Channels
5Severity levels
15minCooldown
<2sDelivery time
Live alert feed

The console your SOC watches.

A working simulation of alerts as they land. Filter by severity, simulate a new detection, or export the current view.

Alert console Active 12
  • Critical
    Gateway • Auto-isolation triggered

    Brute-force attack from hostile nation — endpoint isolated

    Source 185.220.101.34 • Target WEB-SVR-01 • 4,200 attempts in 3 min

  • Critical
    Endpoint • Malware detection

    Crypto miner process terminated — child tree killed

    Process xmrig.exe • Host DEV-PC-07 • PID 8472 + 3 children killed

  • High
    Endpoint • Anomaly detection

    Bulk file exfiltration — 847 files copied to USB in 4 minutes

    User j.smith • Host FIN-PC-03 • Drive E:\ • 2.3 GB total

  • High
    Endpoint • Lateral movement

    SMB lateral movement attempt blocked — port scan detected

    Source 10.0.5.22 • Scanned 445, 3389, 5985 on 14 hosts in 60s

  • High
    Gateway • Threat Cloud

    Connection to known C2 server blocked by Revive Threat Cloud

    Domain malware-cdn[.]xyz • IOC confidence 98% • Source HR-PC-11

  • Medium
    Endpoint • Anomaly detection

    Off-hours login detected — authentication outside business hours

    User r.jones • Host EXEC-PC-01 • Time 02:47 AM local

  • Medium
    Gateway • Geo-fence

    Blocked connection from geo-fenced country

    IP 91.134.xx.xx • Country North Korea • Port 443

  • Medium
    Endpoint • DNS control

    DNS request blocked — gambling category

    Domain bet365.com • Host MKT-PC-05 • Category Gambling

  • Low
    Endpoint • Micro-segmentation

    Outbound connection blocked by firewall policy

    Rule BLOCK-SOCIAL • Dest facebook.com:443 • Host ENG-PC-09

  • Low
    Endpoint • File monitoring

    Suspicious file extension detected — .encrypted

    Path C:\Users\admin\Documents\report.encrypted • Host SRV-DC-02

  • Info
    Endpoint • Heartbeat

    Agent heartbeat restored after 15-minute gap

    Host QA-PC-04 • Last seen 15m ago • Status Online

  • Info
    System • Policy sync

    Policy v3.14 deployed to Engineering group (12 endpoints)

    Policy ENG-STANDARD • Changes: DNS rules, app blocklist updated

Showing 12 alerts • Auto-refresh: 5s
Multi-channel delivery

Wherever your team already works.

Email, Teams or Slack — every alert lands in under two seconds.

Email alerts

Rich HTML mail with severity badges, event detail and one-click action links for fast triage.

[CRITICAL] Brute-force attack detected

Source 185.220.101.34 attempted 4,200 logins against WEB-SVR-01 in three minutes. The endpoint has been auto-isolated. Click to investigate…

Microsoft Teams

Adaptive cards posted to your security channel with severity, source, target and quick-action buttons.

RSReviveSec Bot

CRITICAL — Crypto miner xmrig.exe terminated on DEV-PC-07. Process tree killed (PID 8472 + 3 children).

Slack webhooks

Formatted messages with colour-coded severity bars, clickable IPs and threaded responses.

RSReviveSec

Bulk file exfiltration: 847 files (2.3 GB) copied to USB by j.smith on FIN-PC-03 in four minutes.

Alert capabilities

Less noise. More signal.

Every feature here exists to stop your analysts tuning alerts out.

5 severity levels

Critical, High, Medium, Low and Info — each with its own routing rules, escalation path and channels.

15-minute cooldown

Deduplication groups same-type alerts and suppresses repeats for a configurable cooldown period.

Per-rule configuration

Every detection rule carries its own channel, severity, cooldown and custom message template.

Escalation chains

Unacknowledged alerts escalate on their own — Slack to email to phone — until someone responds.

Smart suppression

Whitelist known-good events, mute during maintenance windows, filter by host group or source IP.

CEF / Syslog forwarding

Forward every alert to your SIEM in CEF format — Splunk, QRadar, Sentinel and Wazuh compatible.

Rule builder

Alert rules you can version.

Configuration

Build the condition, set the action

Create custom rules from conditions, thresholds and actions. Every rule is versioned and can be exported between environments.

  • Condition-based rule logic (AND / OR)
  • Threshold and time-window triggers
  • Custom message templates with variables
  • Auto-action: isolate, kill, block
  • Rule versioning and rollback
  • Export and import JSON rule sets
Rule editor Active
Rule name
Bulk USB exfiltration
Condition
IF file_copy_count > 100 AND target == "USB"
Time window
5 minutes
Severity
High
Actions
Alert → Email, TeamsAction → Auto-isolate
Escalation flow

Escalates until someone owns it.

An unacknowledged threat does not sit still — it climbs the chain until an analyst takes it.

1

Detection

Rule fires and the event is classified by severity.

2

Notify

Alert sent via the configured channels in under two seconds.

3

Escalate

No response in five minutes? It moves to the next tier.

4

Respond

An analyst acknowledges and begins investigating.

5

Resolve

Threat contained, alert closed with notes attached.

Never miss a
critical alert again.

See ReviveSec alerting in action with a personalized demo for your team.

Schedule a demo