> For the complete documentation index, see [llms.txt](https://docs.cipp.app/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.cipp.app/user-documentation/security/incidents/list-check-alerts.md).

# Check Alerts

This page collects the alerts from Check by CyberDrain, a browser plugin that blocks AiTM (Adversary-in-the-Middle) attacks. Check provides real-time protection against phishing and credential theft attempts. Learn more at [docs.check.tech](https://docs.check.tech/) or install the plugin now: [Microsoft Edge](https://microsoftedge.microsoft.com/addons/detail/check-by-cyberdrain/knepjpocdagponkonnbggpcnhnaikajg) | [Chrome](https://chromewebstore.google.com/detail/check-by-cyberdrain/benimdeioplgkhanklclahllklceahbe)

Each row is one page the plugin flagged on a user's machine, so the table tells you which of your users met something suspicious, what they met, and why the plugin acted.

## Table Details

| Column                      | Description                                                                                                               |
| --------------------------- | ------------------------------------------------------------------------------------------------------------------------- |
| Type                        | The kind of detection the plugin reported.                                                                                |
| Url                         | The address the plugin flagged.                                                                                           |
| Reason                      | Why the plugin flagged it.                                                                                                |
| Score                       | The score the plugin gave the page.                                                                                       |
| Threshold                   | The score the plugin was configured to act at. Compare it against **Score** to see how far over the line a detection was. |
| Potential User Name         | The email address of the user the plugin reported the detection for.                                                      |
| Potential User Display Name | That user's display name.                                                                                                 |
| Reported By IP              | The public IP address the report was sent from.                                                                           |
| Timestamp                   | When the alert was recorded. The table is sorted on this, newest first.                                                   |

{% hint style="warning" %}
The user columns are named "potential" for a reason. They carry whatever identity the browser plugin believed it was seeing at the time, which is not an authenticated claim, so treat them as a lead to investigate rather than a confirmed identification.
{% endhint %}

***

## Feature Requests / Ideas

We value your feedback and ideas. Please raise any [feature requests](https://github.com/CyberDrain/CIPP/issues/new?template=feature.yml) on GitHub.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.cipp.app/user-documentation/security/incidents/list-check-alerts.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
