Severity & Status Colors
What each severity color means across Incidents, EDR, UEBA, Red Team, Dark Web, and every other module that ranks findings by risk.
/incidentsThe color scheme
OverviewSeverity Color Scheme
Every module that ranks findings by risk — Incidents, EDR Agents, UEBA, Red Team CVEs, Dark Web findings, Threat Hunt Console, DDoS Detection, Attack Narrative, Attack Surface — uses the same five colors, so severity reads consistently no matter which screen you're on:
| Severity | Color | Meaning |
|---|---|---|
| Critical | Red | Needs immediate attention — the only severity that gets a "danger" color |
| High | Orange | Significant risk, should be worked next |
| Medium | Amber | Worth reviewing, not urgent |
| Low | Mint (brand accent) | Minor, still worth logging |
| Info / Success | Slate gray | Informational, or a clean/resolved result |
Why this matters
Color is the fastest signal an analyst reads when triaging a list of alerts, incidents, or CVEs — a Critical finding should never look the same as a Medium one. If you see two different severities rendering in the same color anywhere in the product, that's a bug — please report it via Support Center → Reporting an issue.
Risk-score bands (EDR, UEBA, Threat Intel confidence)
Where a module shows a 0–100 risk or confidence score instead of a named severity, the same colors apply by threshold:
- 80–100 → red (Critical)
- 60–79 → orange (High)
- 40–59 → amber (Medium)
- 0–39 → mint (Low / good)