1 critical incident is open. Work it now.
1.6k events normalised across 7 sources, evaluated against 19 armed detection rules. Everything below reflects the last 24 hours.
1
Open incidents
1 at critical severity
2
Awaiting triage
Unreviewed detections in the queue
794
Events · 24h
Normalised across every connected source
19
Rules armed
1 source reporting late
Reporting sources: WIN-DC01, Palo Alto Edge, ubuntu-web-01, AWS CloudTrail, WIN-FS02, CrowdStrike Falcon, Legacy VPN Concentrator
Ingest volume
Events per hour across the last 24 hours, UTC.
Severity mix
Events observed in the last 24 hours.
- Critical2
- High5
- Medium2
- Low180
- Info605
Incidents in play
Ranked by risk score, highest first.
Noisiest rules
Detection rules by alerts raised.
- Bulk data egress2
- Impossible travel1
- Encoded PowerShell execution1
- Cloud access key created outside change hours1
- Mass file access1
Riskiest entities
Highest behavioural risk scores.
Source health
Last telemetry received per connected log source.
- 689WIN-DC01Healthy · 2026-09-04 19:13Z
- 423Palo Alto EdgeHealthy · 2026-09-04 19:14Z
- 240ubuntu-web-01Healthy · 2026-09-04 19:14Z
- 161AWS CloudTrailHealthy · 2026-09-04 19:09Z
- 41WIN-FS02Healthy · 2026-09-04 19:11Z
- 4CrowdStrike FalconHealthy · 2026-09-04 19:12Z
- 0Legacy VPN ConcentratorLast seen 8d ago
// Highest exposure
Domain account takeover with credential dumping on WIN-DC01 Risk 96.
96Risk scoreCriticalSeverityAnalystAnalyst of record7d agoOpened
Open the case