All entitiesHunt
UserConfirmed compromised
jsmith
First seen 9d ago · last seen 7d ago
Risk
94
Severe
Observed activity
8 events
| Timestamp (UTC) | Severity | Event type | Message |
|---|---|---|---|
| Critical | Credential Access | Process memory of lsass.exe dumped to disk via comsvcs.dll MiniDump | |
| High | Process Execution | Encoded PowerShell command block executed with hidden window and execution policy bypass | |
| Critical | User Created | Account 'svc_helpdesk_tmp' created by jsmith and added to group 'Domain Admins' | |
| High | Mfa Method Removed | Second-factor method 'Authenticator app' removed from account jsmith | |
| High | Authentication Success | Kerberos TGT issued for jsmith from 185.100.200.50 (logon type 10, RDP) — prior successful logon for this account originated in Chicago, USA 41 minutes earlier | |
| Low | Authentication Failure | Pre-authentication failed for jsmith from 185.100.200.50 (status 0x18: bad password) | |
| Low | Authentication Failure | Pre-authentication failed for jsmith from 185.100.200.50 (status 0x18: bad password) | |
| Low | Authentication Failure | Pre-authentication failed for jsmith from 185.100.200.50 (status 0x18: bad password) |
Profile
- Type
- User
- Risk score
- 94
- Events
- 8
- Relationships
- 4
- First seen
- 2026-09-02 21:15Z
- Last seen
- 2026-09-04 14:39Z
Severity of associated events
- Critical2
- High3
- Medium0
- Low3
- Info0
Linked entities
Relationships derived from shared activity.