Case management
Incidents
Alerts that belong to the same intrusion are merged into an incident with an owner, SLA and audit trail.
Open
3
Critical
2
SLA breached
1
Mean time to contain
2h 14m
INC-1041criticalInvestigatingopened 1970-01-01 05:30:00Z
Phishing-led intrusion with credential dumping on WS-FIN-014
A macro-enabled invoice attachment delivered a PowerShell loader to a finance workstation. The loader established C2, dumped LSASS, and moved laterally to the SQL server via admin shares.
owner: S. Hartonoassets: WS-FIN-014, SRV-SQL-01, SRV-DC-01alerts: 3ATT&CK: T1566.001, T1059.001, T1003.001, T1021.002SLA: 4h response · 2h 10m elapsed
INC-1042highContainedopened 1970-01-01 01:50:00Z
Password spray followed by mailbox rule abuse
A spray campaign from hosting infrastructure compromised one account without MFA. The actor created a hiding inbox rule consistent with business email compromise preparation.
owner: D. Kusumaassets: Entra ID tenant, M365 mailbox r.wijayaalerts: 2ATT&CK: T1110.003, T1114.003, T1078SLA: 8h response · met
INC-1043criticalEradicationopened 1970-01-01 07:45:00Z
Ransomware staging detected on SRV-FILE-03
Canary files were encrypted and shadow copies deleted on the primary file server using a compromised backup service account.
owner: A. Pratamaassets: SRV-FILE-03alerts: 1ATT&CK: T1486, T1490SLA: 1h response · breached by 12m