// Investigation

Entity behaviour

Risk profiles for the users, hosts and addresses seen in telemetry. Risk accrues from the activity an entity participates in, not from any single event.

10entities profiled7at elevated risk

Monitored entities

Ranked by risk score.

EntityTypeRiskReputationLinksLast seen
185.100.200.50IP address
98Severe
Known malicious — bulletproof hosting, 3 threat feeds2
jsmithUser
94Severe
Confirmed compromised4
svc_helpdesk_tmpAccount
91Severe
Attacker-created persistence1
WIN-DC01Host
88Severe
Credential material exposed3
45.61.136.14IP address
76Elevated
Malware distribution — 2 threat feeds1
WS-FIN-004Host
72Elevated
Active persistence mechanism2
ekowalskiUser
68Elevated
No intel1
powershell.exeProcess
54Moderate
No intel2
hlindqvistUser
22Guarded
Investigated — authorised activity1
104.28.211.19IP address
18Low
Baselined — sanctioned auditor transfer service1