How to interpret and respond to alerts detected by Greinfort
Greinfort publishes its Alerts Playbook, a document designed to help users understand the different alerts that can be generated while monitoring an industrial network.
For each type of alert, the guide provides information on its description, priority, probable causes, impact and recommended actions, making it easier to analyze detected events and make decisions in response to potential anomalies or threats.
The document covers alerts generated using Greinfort’s different detection mechanisms, including static rules, Artificial Intelligence and Machine Learning algorithms, IDS, UEBA, Process Mining and honeypots.
The documented scenarios include the detection of new devices or IP addresses, connections through unusual ports, possible fingerprinting or ARP spoofing attempts, communications with public IP addresses and different anomalies identified by the platform’s analysis engines.
The Alerts Playbook also includes a section dedicated to proactive testing, explaining which scenarios can be used to verify that the different threat detection strategies are working correctly.
Download the Alerts Playbook to explore the different detection scenarios and the recommendations associated with each alert in detail.

