Help/troubleshooting
troubleshooting

Incident → Receipt — the full triage flow

Updated June 26, 2026 99 views 0 found this helpful

When PowerSEC raises an incident, you can go from alert to closed receipt without leaving the platform.

1. Receive the alert

You will get an email or dashboard notification:

[PowerSEC] Critical: malware found on site acme.com
  Files: 2  ·  Score: 92  ·  Detected: 14:02 UTC

Click the link or open Dashboard → Incidents.

2. Open the incident

The incident page shows:

  • Type: Malware / Brute Force / Downtime / WAF Attack / etc.
  • Severity: Critical / High / Medium / Low
  • Affected site and which files or endpoints triggered it
  • Runbook steps if available for your plan

3. Follow the runbook

For each incident type, PowerSEC shows step-by-step actions:

Malware detected:

  1. Review flagged files in the incident detail
  2. Click Quarantine on any suspicious file
  3. Investigate the likely entry point (vulnerable plugin?)
  4. Update or disable the vulnerable plugin
  5. Re-scan to confirm clean
  6. Mark resolved

Brute force:

  1. Block the attacking IP from the Firewall tab
  2. Reset any compromised admin passwords
  3. Enable 2FA if not already active
  4. Mark resolved

4. Mark as resolved

Click Resolve incident at the top of the incident page. You can add a resolution note for your audit trail.

5. Review

For Critical incidents: 15 minutes after resolution, review what allowed the attack and update your rules.

Couldn't find what you're looking for?

Browse more articles or reach out to our support team.

Browse all articles Email support
Incident → Receipt — the full triage flow — PowerSEC help | PowerSEC