Structural search

Search everything you’ve investigated

9 cases in operational memory — matched by the patterns and entities that fired, not by keywords.

Filter by concept

Filter by outcome

All cases

Splunk — WIN-DC01 (12h window)

APP-01 · 2026-07-09

Confirmed threat
Normal Authentication Baseline Credential Compromise Credential Abuse
Julius Jenkins

EDR — Endpoint Activity (LAPTOP-B123)

LAPTOP-B123 · 2026-07-09

Confirmed threat
File Encryption Activity Command and Control Beacon Suspicious Process Execution
Julius Jenkins

AcmeCloud Audit Logs — unrecognized source

2026-07-09

Confirmed threat
Julius Jenkins

IDS + Scanner — WEB-01 (203.0.113.55)

WEB-01 · 2026-07-09

Confirmed threat
Known Exploited Vulnerability Exposed Public-Facing Vulnerable Service Port Scan Activity
Julius Jenkins

Same pattern on bob@corp.example

WIN-DC01 · 2026-06-14

Confirmed threat
Credential Abuse Credential Compromise

What was done

  • Disabled the source IP at the perimeter firewall
  • Forced password reset for bob@corp.example
  • Opened ticket INC-3391 and escalated to Tier 2
Dana Reeves (SOC Lead) 38 min

KEV exposure on WEB-03

WEB-03 · 2026-06-02

Confirmed threat
Port Scan Activity Known Exploited Vulnerability Exposed Public-Facing Vulnerable Service

What was done

  • Patched nginx to a fixed build within the maintenance window
  • Added a WAF rule blocking the exploit path as interim mitigation
  • Rescanned to confirm the CVE no longer matched
Marcus Hale (Analyst) 3 h 5 min

Similar brute-force from 198.51.100.22

WIN-DC02 · 2026-05-30

False positive
Credential Abuse

What was done

  • Traced source IP to the internal Red Team scanner
  • Marked Normal and added scanner IP to the allowlist
Marcus Hale (Analyst) 12 min

Ransomware on FINANCE-04

FINANCE-04 · 2026-05-11

Confirmed threat
Suspicious Process Execution File Encryption Activity Command and Control Beacon

What was done

  • Isolated the host from the network within 4 minutes
  • Killed the PowerShell process and blocked the C2 domain
  • Restored encrypted files from the 02:00 backup snapshot
  • Attempted user-level quarantine first — too slow, host spread
Dana Reeves (SOC Lead) 1 h 6 min

Off-hours bulk download by dana

corp-financials · 2026-04-22

Confirmed threat
Off-Hours Data Access Anomalous Data Volume Data Exfiltration to Personal Cloud

What was done

  • Suspended the user account pending HR review
  • Revoked personal-cloud upload via DLP policy
  • Preserved audit logs for legal hold
Priya Nadin (CISO) 2 h 20 min