Security Dashboard
EDR Active
Monitoring
Active alerts
3
2 fewer than last week
Endpoints online
47/50
3 offline (expected)
Threats blocked / 30d
284
+41 vs prior month
Avg response time
8m
SLA: <15m
Recent alerts
View all →
SeverityAlertEndpointTimeStatus
HIGH
Credential dump — LSASS
PowerShell encoded · Mimikatz pattern
ACME-WS-047
14m ago
Investigating
MED
Anomalous DNS beaconing
60s interval · C2 pattern
ACME-SRV-02
1h ago
Investigating
INFO
New device enrolled
EDR sensor deployed
ACME-LT-14
2h ago
Resolved
Endpoint health
View all →
ACME-SRV-01
Domain Controller
Clean
ACME-WS-047
Finance Workstation
Alert
ACME-LT-14
Marketing Laptop
Clean
This month
Critical threats blocked7
Threat hunts completed4
Mean time to detect4m 12s
Mean time to contain8m 34s
Uptime SLA100%
Alert Feed
All security alerts — last 30 days
2 Investigating284 Resolved
SeverityAlertEndpointTimeStatus
HIGH
Credential dump attempt — LSASS
PowerShell encoded · Mimikatz pattern detected
ACME-WS-047
14m ago
Investigating
MED
Anomalous DNS beaconing pattern
60s interval · External host · C2 candidate
ACME-SRV-02
1h ago
Investigating
INFO
New endpoint enrolled
EDR sensor deployed and communicating
ACME-LT-14
2h ago
Resolved
HIGH
Persistence via scheduled task
T1053.005 · Cobalt Strike stager · Removed
ACME-WS-031
6h ago
Contained
CRIT
Ransomware pre-execution blocked
Ryuk variant · LOLBin staging · Isolated pre-detonation
ACME-SRV-01
3d ago
Contained
MED
Impossible travel — admin account
US → Eastern Europe · 4 min window · MFA enforced
Identity
5d ago
Blocked
Endpoints
50 enrolled · 47 online · EDR active on all
47 Clean 1 Alert2 Offline
DeviceStatusLast seenRiskOS
ACME-SRV-01
Domain Controller
Online
Just now
Server 2022
ACME-WS-047
Finance Workstation
Alert
2m ago
Win 11 Pro
ACME-LT-14
Marketing Laptop
Online
8m ago
macOS 14.4
ACME-WS-012
Reception Desk
Online
15m ago
Win 10 Pro
ACME-LT-08
Sales Laptop
Offline
2d ago
Win 11 Pro
Threat Hunts
Proactive MITRE ATT&CK aligned hunts
StatusHuntScopeDateResult
DONE
T1059 — PowerShell / Script execution
MITRE ATT&CK · 50 endpoints · No IOCs found
All endpoints
2d ago
Clean
DONE
T1078 — Valid account abuse
Privileged account lateral movement check
AD / Identity
5d ago
Clean
SCHED
T1547 — Boot/logon autostart persistence
Registry run keys, startup folders, services
All endpoints
Tomorrow
Scheduled
Reports
Monthly executive summaries and incident reports
Monthly Executive Summary — May 2025
High-level overview of threat activity, response metrics, and environment health. Board-ready format.
Delivered Jun 2, 2025
Download PDF
Incident Report — Ransomware Pre-Exec
Full technical report on the Ryuk variant blocked May 14. Root cause, IOCs, and remediation steps.
Delivered May 15, 2025
Download PDF
Threat Hunt Report — T1059
Results of MITRE T1059 PowerShell hunt across all 50 endpoints. No IOCs found.
Delivered Jun 12, 2025
Download PDF
Monthly Executive Summary — Apr 2025
April threat landscape, endpoint health, and blocked threat statistics.
Delivered May 2, 2025
Download PDF
Threat Intelligence
Active advisories relevant to your environment
SeverityAdvisoryTypeDateAction
CRIT
Rhysida ransomware — healthcare vertical surge
New LOLBin persistence · Tennessee Valley active
Ransomware
1d ago
Monitoring
HIGH
BEC campaign — CFO wire fraud targeting SMBs
AiTM MFA bypass · O365 credential harvesting
BEC / Fraud
2d ago
Monitoring
MED
PowerShell LOTL campaign — SMB sector
WMI subscription abuse · Cobalt Strike stager
LOTL
4d ago
Mitigated
Settings
Account and notification preferences
Account
Organization—
Email—
Assigned analystJ. Rodriguez · GCFA