// Investigation
Entity behaviour
Risk profiles for the users, hosts and addresses seen in telemetry. Risk accrues from the activity an entity participates in, not from any single event.
10entities profiled7at elevated risk
Monitored entities
Ranked by risk score.
| Entity | Type | Risk | Reputation | Links | Last seen |
|---|---|---|---|---|---|
| 185.100.200.50 | IP address | 98Severe | Known malicious — bulletproof hosting, 3 threat feeds | 2 | |
| jsmith | User | 94Severe | Confirmed compromised | 4 | |
| svc_helpdesk_tmp | Account | 91Severe | Attacker-created persistence | 1 | |
| WIN-DC01 | Host | 88Severe | Credential material exposed | 3 | |
| 45.61.136.14 | IP address | 76Elevated | Malware distribution — 2 threat feeds | 1 | |
| WS-FIN-004 | Host | 72Elevated | Active persistence mechanism | 2 | |
| ekowalski | User | 68Elevated | No intel | 1 | |
| powershell.exe | Process | 54Moderate | No intel | 2 | |
| hlindqvist | User | 22Guarded | Investigated — authorised activity | 1 | |
| 104.28.211.19 | IP address | 18Low | Baselined — sanctioned auditor transfer service | 1 |