All entities
UserConfirmed compromised

jsmith

First seen 9d ago · last seen 7d ago

Risk
94
Severe
Hunt

Observed activity

8 events

Timestamp (UTC)SeverityEvent typeMessage
CriticalCredential AccessProcess memory of lsass.exe dumped to disk via comsvcs.dll MiniDump
HighProcess ExecutionEncoded PowerShell command block executed with hidden window and execution policy bypass
CriticalUser CreatedAccount 'svc_helpdesk_tmp' created by jsmith and added to group 'Domain Admins'
HighMfa Method RemovedSecond-factor method 'Authenticator app' removed from account jsmith
HighAuthentication SuccessKerberos TGT issued for jsmith from 185.100.200.50 (logon type 10, RDP) — prior successful logon for this account originated in Chicago, USA 41 minutes earlier
LowAuthentication FailurePre-authentication failed for jsmith from 185.100.200.50 (status 0x18: bad password)
LowAuthentication FailurePre-authentication failed for jsmith from 185.100.200.50 (status 0x18: bad password)
LowAuthentication FailurePre-authentication failed for jsmith from 185.100.200.50 (status 0x18: bad password)

Profile

Type
User
Risk score
94
Events
8
Relationships
4
First seen
2026-09-02 21:15Z
Last seen
2026-09-04 14:39Z

Severity of associated events

  • Critical2
  • High3
  • Medium0
  • Low3
  • Info0

Linked entities

Relationships derived from shared activity.