> ## Documentation Index
> Fetch the complete documentation index at: https://syteca.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Default Alerts

> Catalog of the alerts that ship preconfigured with Syteca — covering fraudulent activity, data leakage, potentially illicit activity, and non-work-related activity across Windows and Linux Clients.

Syteca ships with a set of **default alerts** that trigger on common categories of forbidden activity — fraudulent actions on Windows and Linux Clients, data leakage via cloud services, illicit website categories, and non-work-related applications and websites. The default alerts are **enabled by default but not assigned to any Clients** — assign them to the Clients you want to monitor before they take effect.

For the alert workflow (creating, editing, assigning, deleting), see [Alerts](/docs/session-monitoring/alerts). For the rule-engine reference, see [Alert rules](/docs/session-monitoring/alert-rules).

## How default alerts work

* **Added automatically** when the Syteca Application Server is installed or updated.
* **Risk level: High** by default for every default alert.
* **Enabled, not assigned** — visible on the Alerts page, but won't trigger until you assign Clients via [Edit Alert](/docs/session-monitoring/alerts#edit-an-alert) or [Manage Multiple Alerts](/docs/session-monitoring/alerts#assign-alerts-to-clients).

You can edit any default alert just like any other alert:

* Enable / disable
* Change the risk level
* Configure notification options (email, tray, on-screen warning)
* Enable additional actions (block user, kill process)
* Delete

To hide all default alerts on the Alerts page (to focus on custom ones), select **Hide Default** in the **Hide None** drop-down at the top of the Alerts page.

Default alerts are organized into four categories.

## Fraudulent Activity

| Alert                                      | Triggered when...                                                                                                                                                                                       | OS      |
| ------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------- |
| **Cleanup applications**                   | A user opens a PC cleanup application such as CCleaner, PC Decrapifier, File Shredder, or CleanUp.                                                                                                      | Windows |
| **The command prompt**                     | A user opens the command prompt.                                                                                                                                                                        | Windows |
| **Changing the Windows date/time**         | A user changes the date & time settings.                                                                                                                                                                | Windows |
| **Editing the Windows Registry**           | A user edits the Windows Registry using the Windows Registry Editor.                                                                                                                                    | Windows |
| **Downloading a file using a web browser** | A user downloads a file via Chrome, Firefox, or Internet Explorer.                                                                                                                                      | Windows |
| **Uploading a file using a web browser**   | A user uploads a file via Chrome, Firefox, or Internet Explorer.                                                                                                                                        | Windows |
| **Hacking software**                       | A user uses any kind of hacking software such as Angry IP Scanner, HashCat, Burp Suite, Cain & Abel, Ettercap, John The Ripper, Kali, Metasploit, Nmap, Snort, THC Hydra, Wapiti, Wifite, or Wireshark. | Windows |
| **IIS binding settings**                   | A user changes the IIS binding settings.                                                                                                                                                                | Windows |
| **Internet Explorer proxy settings**       | A user changes the Internet Explorer proxy settings.                                                                                                                                                    | Windows |
| **Remote desktop connection**              | A user initiates an RDP connection to another computer.                                                                                                                                                 | Windows |
| **Creating/editing of a Windows user**     | A user adds or edits a Windows user.                                                                                                                                                                    | Windows |
| **Installation detection**                 | A user runs commands for installation.                                                                                                                                                                  | Linux   |
| **Root privileges**                        | A user grants root privileges to another user.                                                                                                                                                          | Linux   |
| **Adding a user**                          | A user adds a user.                                                                                                                                                                                     | Linux   |

## Data Leakage

| Alert                           | Triggered when...                                                                                                                                                                                                                                                                                    | OS      |
| ------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------- |
| **Cloud backup**                | A user opens a cloud backup service such as ADrive, AltDrive, Backblaze, Backup Lizard, Bitcasa, Carbonite, Comodo Backup, CrashPlan, ElephantDrive, IDrive, Jottacloud, Jungle Disk, Livedrive, Mozy, NitroBackup, Nomadesk, OpenDrive, SafeSync, SpiderOak, SugarSync, Symform, Zoolz, and others. | Windows |
| **Cloud file sharing**          | A user shares files via a cloud-based service such as 2Big2Send, 4shared, CloudApp, DropSend, FileDropper, JustBeamIt, MailBigFile, Minus.com, pastebin.com, RapidShare, SendYourFiles, WeTransfer, Wikisend, YouSendIt, and many others.                                                            | Windows |
| **Cloud storage**               | A user visits cloud storage websites: Dropbox.com, drive.google.com, onedrive.live.com, Otixo, box.com, Fluxiom, spideroak.com, amazon.com, justcloud.com, livedrive.com, sugarsync.com, code42.com/crashplan, zipcloud.com, mozy.com, mega.nz, adrive.com, bitcasa.com, icloud.com, and others.     | Windows |
| **Desktop email clients**       | A user opens AOL Mail, Microsoft Outlook, Windows Live Mail, IBM Notes, Thunderbird, Postbox, Novell GroupWise, or The Bat!                                                                                                                                                                          | Windows |
| **FTP access**                  | A user visits an FTP website.                                                                                                                                                                                                                                                                        | Windows |
| **Online email services**       | A user uses mail.google.com, login.live.com, login.yahoo.com, my.screenname.aol.com, zoho.com, mail.com, inbox.com, gmx.com, icloud.com, mail.lycos.com, hushmail.com, or mail.yandex.com.                                                                                                           | Windows |
| **Screen sharing applications** | A user opens TeamViewer, Deskhop, Screenleap, ShowMyPC, Mingle View, Apache OpenMeetings, Mikogo, LogMeIn, join.me, Remote Access Viewer, WebEx, GoToMeeting, AnyMeeting, or Zoom.                                                                                                                   | Windows |
| **Device mounting**             | A user attempts to execute commands to mount devices on Linux servers.                                                                                                                                                                                                                               | Linux   |

## Potentially Illicit Activity

| Alert                   | Triggered when...                                                                                                                                                                                                                                                                                                                                         | OS      |
| ----------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------- |
| **Adult websites**      | A user visits flirt4free.com, ebaumsworld.com, imlive.com, freeones.com, redtube.com, cam4.com, adultfriendfinder.com, youporn.com, xnxx.com, livejasmin.com, G.e-hentai.org, Nudevista.com, Adam4adam.com, or Literotica.com. *Also triggers on any website containing `xxx` or `porn` in the URL.*                                                      | Windows |
| **BitTorrent clients**  | A user opens a BitTorrent client such as uTorrent, Vuze, Tixati, Torch, qBittorrent, Transmission, Deluge, or BitLord.                                                                                                                                                                                                                                    | Windows |
| **BitTorrent websites** | A user visits thepiratebay, kat.cr, torrentz.eu, extratorrent, yts, eztv, 1337x, isohunt, bitsnoop, or rarbg.                                                                                                                                                                                                                                             | Windows |
| **Gambling websites**   | A user visits grosvenorcasinos.com, leovegas.com, 777.com, casino.com, foxycasino.com, casino.betway.com, bet365.com, titanbet.com, 888casino.com, or europacasino.com. *Also triggers on any website containing `casino` or `poker` in the URL.*                                                                                                         | Windows |
| **Proxy anonymizers**   | A user visits proxify.com, anonymouse.org, hidemyass.com, the-cloak.com, bind2.com, maskedip.com, anonymizer.com, proxy.org, newipnow\.com, zophar.net, proxysite.com, dontfilter.us, blewpass.com, kproxy.com, alter-ip.com, proxy.my-addr.com, megaproxy.com, proxfree.com, fresh-proxy.appspot.com, youhide.com, proxywebsite.org, or the Tor browser. | Windows |

## Non-Work-Related Activity

| Alert                          | Triggered when...                                                                                                                                                                                                                                                                                                                    | OS      |
| ------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------- |
| **Dating websites**            | A user visits match.com, okcupid.com, gotinder.com, meetup.com, pof.com, zoosk.com, eharmony.com, badoo.com, christianmingle.com, ourtime.com, datehookup.com, howaboutwe.com, seniorpeoplemeet.com, speeddate.com, chemistry.com, or jdate.com.                                                                                     | Windows |
| **Desktop media players**      | A user opens Windows Media Player, BS.Player, PotPlayer, DivX Player, GOM Player, KMPlayer, VLC, Kantaris Media Player, Media Player Classic, SMPlayer, DAPlayer, or iTunes.                                                                                                                                                         | Windows |
| **Instant messengers**         | A user opens Pidgin, MSN Messenger, Yahoo! Messenger, Google Talk, Digsby, ICQ, Miranda IM, or Trillian.                                                                                                                                                                                                                             | Windows |
| **Job search websites**        | A user visits indeed.com, monster.com, glassdoor.com, jobsearch.com, careerbuilder.com, simplyhired.com, jobdiagnosis.com, beyond.com, ziprecruiter.com, snagajob.com, theladders.com, dice.com, elance.com/upwork.com, linkedin.com, peopleperhour.com, linkup.com, careerarc.com, freelancer.com, aol-careers.com, or usajobs.gov. | Windows |
| **Online gaming websites**     | A user visits eune.leagueoflegends, battle.net, steampowered.com, dota2, trionworlds, hirezstudios, minecraft, worldoftanks, swtor.com, kongregate.com, armorgames, addictinggames.com, newgrounds.com, popcap.com, crazymonkeygames.com, pch.com, zynga.com, totaljerkface.com, deadwhale.com, or plarium.com.                      | Windows |
| **Online video websites**      | A user visits YouTube, dailymotion.com, vimeo, gopro.com, ted.com, on.aol.com, mtv.com, funnyordie.com, break.com, metacafe.com, or veoh.com.                                                                                                                                                                                        | Windows |
| **Social networking websites** | A user visits facebook, X, linkedin, pinterest, plus.google.com, tumblr, instagram, vk.com, flickr, vine.co, meetup.com, tagged.com, ask.fm, meetme.com, classmates.com, foursquare, tripadvisor, weeworld.com, mixi.jp, myspace.com, myheritage.com, or schtik.com.                                                                 | Windows |

## Related

<CardGroup cols={2}>
  <Card title="Alerts" icon="bell" href="/docs/session-monitoring/alerts">
    Assign default alerts to Clients, edit them, configure response actions.
  </Card>

  <Card title="Alert rules reference" icon="square-code" href="/docs/session-monitoring/alert-rules">
    Build custom alerts following the patterns the defaults illustrate.
  </Card>

  <Card title="USB Devices" icon="usb" href="/docs/session-monitoring/usb-devices/overview">
    The complementary detection layer for physical-channel data movement.
  </Card>

  <Card title="File upload monitoring" icon="upload" href="/docs/session-monitoring/file-upload-monitoring">
    A focused alternative to the browser-based default alerts above.
  </Card>
</CardGroup>
