Made by Gaurav Jain
Every detection across the estate, auto-triaged and correlated. Select, investigate, and respond — the fleet has already done the enrichment.
48 of 48 alerts
| medium | Suspicious PowerShell with encoded command T1059.001·Execution | ◈ENG-BUILD-04 | Sysmon | 47 | 1h ago | False positive | |
| critical | Mass file encryption on file server T1486·Impact | ☁DEV-CI-09 | EDR-Falcon | 96 | 1h ago | Investigating | |
| high | Defender tampering — service disabled T1562.001·Defense Evasion | ◈K8S-NODE-17 | Sysmon | 84 | 2h ago | Resolved | |
| critical | OAuth consent grant to unknown app T1550.001·Persistence·K. Odigie | ☁EXCH-01 | AzureAD | 92 | 3h ago | Investigating | |
| critical | Defender tampering — service disabled T1562.001·Defense Evasion·N. Reyes | ✉admin@corp.local | Sysmon | 89 | 4h ago | Contained | |
| critical | Mass file encryption on file server T1486·Impact·S. Fischer | ⬡185.220.101.34 | EDR-Falcon | 82 | 4h ago | Investigating | |
| high | Suspicious PowerShell with encoded command T1059.001·Execution·J.Варга | ◑l.fontaine | Sysmon | 79 | 4h ago | Resolved | |
| high | Mass file encryption on file server T1486·Impact | ✉r.blackwood@corp.local | EDR-Falcon | 62 | 4h ago | False positive | |
| high | Beaconing to known C2 infrastructure T1071.001·Command & Control | ☁K8S-NODE-17 | Zeek | 70 | 4h ago | False positive | |
| medium | Impossible travel — sign-in anomaly T1078·Initial Access·S. Fischer | ⬡193.32.162.44 | AzureAD | 65 | 5h ago | New | |
| high | Defender tampering — service disabled T1562.001·Defense Evasion | ◑l.fontaine | Sysmon | 72 | 7h ago | Resolved | |
| medium | Credential dumping via LSASS access T1003.001·Credential Access | ⬡104.21.5.178 | EDR-Falcon | 59 | 8h ago | Contained | |
| high | Scheduled task persistence created T1053.005·Persistence | ☁WIN-DC02 | Sysmon | 74 | 8h ago | New | |
| high | Phishing link clicked — credential harvest T1566.002·Initial Access·J.Варга | ⬡45.142.212.61 | Okta | 68 | 9h ago | Resolved | |
| low | Kerberoasting — abnormal TGS requests T1558.003·Credential Access·K. Odigie | ⬡45.142.212.61 | Sentinel | 15 | 9h ago | Resolved | |
| high | Scheduled task persistence created T1053.005·Persistence | ⬡193.32.162.44 | Sysmon | 67 | 10h ago | False positive | |
| high | Kerberoasting — abnormal TGS requests T1558.003·Credential Access | ◑k.nordstrom | Sentinel | 79 | 10h ago | Resolved | |
| medium | Data staged in archive before exfil T1560.001·Collection·N. Reyes | ☁CROWN-VAULT-01 | EDR-Falcon | 52 | 10h ago | False positive | |
| critical | DNS tunneling detected T1071.004·Command & Control·K. Odigie | ◑svc_backup | Suricata | 85 | 10h ago | Contained | |
| critical | Impossible travel — sign-in anomaly T1078·Initial Access·M. Chen | ☁EXCH-01 | AzureAD | 87 | 10h ago | Resolved | |
| medium | Lateral movement via SMB admin share T1021.002·Lateral Movement | ◈LNX-WEB-03 | Zeek | 40 | 10h ago | Resolved | |
| info | Exfiltration over web service T1567.002·Exfiltration | ◈SQL-PROD-01 | Suricata | 8 | 10h ago | New | |
| high | Ransomware canary file modified T1486·Impact | ◑r.blackwood | EDR-Falcon | 65 | 11h ago | Resolved | |
| medium | Data staged in archive before exfil T1560.001·Collection | ⬡45.142.212.61 | EDR-Falcon | 48 | 12h ago | Investigating | |
| high | OAuth consent grant to unknown app T1550.001·Persistence | ✉a.petrov@corp.local | AzureAD | 76 | 12h ago | Contained | |
| low | Impossible travel — sign-in anomaly T1078·Initial Access | ☁DEV-CI-09 | AzureAD | 22 | 12h ago | New | |
| info | OAuth consent grant to unknown app T1550.001·Persistence·K. Odigie | ◈DEV-CI-09 | AzureAD | 14 | 13h ago | Resolved | |
| info | Exfiltration over web service T1567.002·Exfiltration | ◑svc_backup | Suricata | 16 | 13h ago | Investigating | |
| low | Beaconing to known C2 infrastructure T1071.001·Command & Control·J.Варга | ⬡193.32.162.44 | Zeek | 20 | 14h ago | New | |
| high | Ransomware canary file modified T1486·Impact | ⬡185.220.101.34 | EDR-Falcon | 69 | 14h ago | False positive | |
| high | Kerberoasting — abnormal TGS requests T1558.003·Credential Access | ✉s.okonkwo@corp.local | Sentinel | 82 | 14h ago | Investigating | |
| high | Credential dumping via LSASS access T1003.001·Credential Access·J.Варга | ☁CROWN-VAULT-01 | EDR-Falcon | 66 | 15h ago | Investigating | |
| critical | Ransomware canary file modified T1486·Impact | ◈MKT-WKS-4410 | EDR-Falcon | 97 | 15h ago | False positive | |
| critical | Beaconing to known C2 infrastructure T1071.001·Command & Control·N. Reyes | ☁WIN-DC01 | Zeek | 95 | 16h ago | False positive | |
| medium | Suspicious PowerShell with encoded command T1059.001·Execution·S. Fischer | ☁OPS-JUMP-01 | Sysmon | 42 | 17h ago | New | |
| critical | Cloud IAM privilege escalation T1098·Privilege Escalation | ◈AWS-EC2-i-0af3 | CloudTrail | 87 | 17h ago | False positive | |
| high | Lateral movement via SMB admin share T1021.002·Lateral Movement·N. Reyes | ☁WIN-DC01 | Zeek | 84 | 17h ago | False positive | |
| high | Credential dumping via LSASS access T1003.001·Credential Access·K. Odigie | ◈LNX-WEB-03 | EDR-Falcon | 69 | 18h ago | Resolved | |
| high | Cloud IAM privilege escalation T1098·Privilege Escalation·M. Chen | ◑r.blackwood | CloudTrail | 62 | 19h ago | False positive | |
| high | Exfiltration over web service T1567.002·Exfiltration·J.Варга | ✉m.tanaka@corp.local | Suricata | 63 | 19h ago | Resolved | |
| medium | Data staged in archive before exfil T1560.001·Collection·T. Alavi | ◑s.okonkwo | EDR-Falcon | 40 | 19h ago | New | |
| high | DNS tunneling detected T1071.004·Command & Control | ◈WIN-DC01 | Suricata | 65 | 20h ago | Contained | |
| medium | Scheduled task persistence created T1053.005·Persistence | ◈SQL-PROD-01 | Sysmon | 55 | 20h ago | Contained | |
| high | Lateral movement via SMB admin share T1021.002·Lateral Movement | ◈WIN-DC02 | Zeek | 64 | 20h ago | Resolved | |
| info | Cloud IAM privilege escalation T1098·Privilege Escalation | ◑k.nordstrom | CloudTrail | 10 | 22h ago | New | |
| medium | Phishing link clicked — credential harvest T1566.002·Initial Access·T. Alavi | ☁VPN-GW-02 | Okta | 46 | 22h ago | Contained | |
| high | Phishing link clicked — credential harvest T1566.002·Initial Access | ☁ENG-BUILD-04 | Okta | 84 | 22h ago | New | |
| medium | DNS tunneling detected T1071.004·Command & Control·J.Варга | ☁OPS-JUMP-01 | Suricata | 48 | 23h ago | Contained |