Prepare the safe path
- An incident is evidence that a documented detector threshold was met; it is not proof of compromise.
- Privacy and retention settings determine which hostnames and device attribution can be included.
- Incident detection never creates a live DNS rule automatically.
1 Start with the active workload
Use the summary to see active and high-priority counts. The table initially includes every retained incident and sorts by the latest detection time.
2 Search or narrow the table
Search across incident names, detector types, devices, profiles, statuses, alert state, retained evidence, and eligible hostname samples. Type, Device / scope, Severity, and Status filters can be combined.
3 Sort the operational view
Choose a sortable column heading to order by severity, incident name, device or scope, status, last detection time, or occurrence count. Choose the same heading again to reverse direction.
4 Open only the evidence you need
View details shows the measurement window, last detection, occurrence count, alert delivery, scope, recorded evidence, representative retained hostnames, detector threshold, limitations, and privacy coverage.
5 Record a response
Acknowledge records that the incident is under review. Resolve closes the operational item without deleting its evidence. Reopen returns a resolved item to the active queue.
6 Treat recommendations as a starting point
Review suggestions do not change policy. When a Policy Lab option exists, it creates only a read-only simulation; live activation remains a separate deliberate action.
Confirm the result
You can find an incident quickly, understand why it was raised and what data supports it, then record its operational status without silently changing DNS protection.
Protect the account while you work
- Do not share screenshots containing real hostnames, device names, household members, employees, or customer identities.
- A generated-looking hostname, volume change, new-domain burst, NXDOMAIN pattern, or block-rate increase can have legitimate explanations. Investigate context before changing policy.
When the expected result does not appear
Search returns no incidents.
Clear the current filters and try a device name, detector type, status, or retained hostname. Privacy-protected evidence may not contain a hostname.
An account incident has no device.
The detector may be account-wide or the underlying activity may be anonymized. QueryWarden does not reconstruct device identity from private aggregates.
A recommendation cannot be activated from the incident.
This is intentional. Open the read-only Policy Lab simulation, inspect measured impact, and use the separate authorized activation workflow only if justified.