What you should know about target alerts

What are alerts

During the investigation phase, various evidence is collected from the target device. In addition to collecting evidence to be analyzed, it can be useful receive "alerts" in real time on special events that concern the target via e-mail or a notification on the RCS Console.

For example, if awaiting evidence from a target for a long time, an alert rule can be created to send an e-mail and record a log for each piece of evidence received. This way, users are immediately notified when the target resumes activities. The rule can be disabled later and evidence can simply be viewed as it arrives.

Alert rule utilities

Alert rules inform the system when alerts must be sent for evidence or synchronizations. Furthermore, they can be used to automatically assign certain evidence levels of relevance that can be used in the analysis phase to select evidence.

Alert rule application field

Rules can be created to alert the arrival of evidence in the system at the following levels:

NOTE: each user will be alerted according to their set rules.

Alert process

The alert process is described below:

NOTE: sending an e-mail is optional.

Phase Description
1

The Analyst creates the rules to be alerted when special evidence arrives or when the target device is synchronized. Rules log the alerts, notify them on the RCS Console and send them via e-mail (optional).

2

The system taps incoming evidence and compares them with the alert rules.

If the evidence... Then...

corresponds to an alert rule

The system logs information as evidence and generates an alert that automatically applies the selected level of relevance. An e-mail notification can be sent by the system as an option.

does not correspond to an alert rule

the system logs the information as evidence without generating an alert.

3

The Analyst receives an alert e-mail (if set by the alert rule) and checks the alert log. The evidence that generated an alert can be directly viewed from the alert.

4

After checking, the Analyst deletes the alert logs.