Incident Response
Investigations
Case files for active and historical investigations. Each incident bundles related alerts, the AI Co-Analyst's findings, and a chronological timeline of analyst + automation activity.
Open
1
Investigating
3
Contained
1
Closed
0
Mean risk
61/100
Active investigations · 5
Click any case to open the timeline and AI summary.
- INC-0042criticalinvestigatingSuspected credential compromise on finance workstationCredential TheftDefence EvasionInitial Access2 affected · 2 linked alerts · 8 eventsRisk86Updated3m ago
- INC-0041highopenEdge brute-force campaign against /adminBrute ForceCredential Stuffing2 affected · 1 linked alerts · 3 eventsRisk64Updated8m ago
- INC-0039mediuminvestigatingAnomalous data egress — personal Drive uploadExfiltration1 affected · 1 linked alerts · 2 eventsRisk48Updated30m ago
- INC-0040highinvestigatingService account creates scheduled task on DCPersistencePrivilege Escalation2 affected · 1 linked alerts · 4 eventsRisk71Updated35m ago
- INC-0038mediumcontainedPhishing wave impersonating Microsoft 365PhishingCredential Harvesting1 affected · 1 linked alerts · 3 eventsRisk38Updated2h ago