Documentation

Changes & incidents

How individual differences become one reviewable item, and what the severity and confidence on it mean.

From change to incident

Each conclusive observation is compared against known state. A difference becomes a change event. Change events for a zone inside a correlation window are then evaluated against a set of risk rules; when one matches, the events are grouped into an incident.

Risk patterns

  • Possible domain takeover — nameservers changed, DS removed, addresses moved to a previously unseen ASN, new certificate issued, MX changed. Two or more indicators raise it to HIGH; more raise it to CRITICAL.
  • Mail interception risk — MX changed, SPF weakened or DMARC relaxed, strengthened by a new TLS certificate on the mail path.
  • Routing anomaly — DNS unchanged but origin ASN changed, RPKI became invalid, or endpoint reachability shifted.
  • Unexpected certificate issuance — a certificate seen in CT for your domain that you did not expect.

Severity and confidence

Severity is how bad it would be if real: info, low, medium, high, critical. Confidence is how sure the correlation is: low through very_high. A change inside a declared maintenance window is dampened one severity level rather than suppressed.

Review workflow

Every change and incident carries a review state, so triage is recorded rather than remembered:

  • Unreviewed — the default; the actionable state.
  • Investigating — picked up by someone.
  • Expected — a known, authorised change.
  • Unauthorized — confirmed bad; the one state that stays visually loud.
  • False positive / Resolved — terminal states.

Set them from the Events or Investigate views, or from a zone's own Timeline and Incidents tabs.