Security Alerts & Incident Triaging
Edit ArticleInvestigating high-priority threat detections and triaging security anomalies.
Sentinel Operations Team
5 min read
Updated August 28, 2026
v3.2When an endpoint policy is violated (e.g. unauthorized USB insertion, dangerous process launch), Sentinel creates a structured alert with an interactive event timeline.
Security Alert Triage — Suspicious USB Insertion & File Export
Critical Alert
Managed Endpoints
412 Online / 428 TotalSync: 12s ago
| Status | Hostname | Logged-In User | OS Build | Agent |
|---|---|---|---|---|
| Active | LAPTOP-FIN-019 | corp\m.vasquez | Win 11 (23H2) | v3.2.4 |
| Active | WS-ENG-8821 | corp\d.kim | Ubuntu 22.04 | v3.2.4 |
| High CPU | MACBOOK-MKT-04 | corp\a.wright | macOS 14.5 | v3.2.0 (Update) |
1Incident Timeline
21-Click Remediation
Figure 4.1: Security alert investigation modal detailing unauthorized USB mass storage connection and file export attempt.
Tags:#Security Alerts#Incident Triage#Remediation
Was this documentation page helpful?
Your technician feedback helps our team continuously improve Sentinel guides.

