Defensive Intelligence Platform

Outsmart Threats
Before They Strike.

Analyze, detect, and respondbefore they become breaches.

Streamline Your Defense with an Intelligence Edge.

AletheiaAletheia
Alert Management
23 threats found
TimestampMitre TechniqueDescriptionSeverity
14:20:05T1530S3 Data Exfiltration · Anomalous GetObject volume from unknown IP · bucketclient-financial-recordsCritical
14:18:22T1562.001CloudTrail Logging Disabled · StopLogging event detected from root account · regionus-east-1Critical
14:15:10T1078.004Unusual Access Pattern · Successful login from geographically improbable location · userdev-ops-svcHigh
13:58:19T1530S3 Bucket Public Discovery · Enumeration attempt detected via ListBuckets API · src94.232.x.xMedium
13:42:07T1098IAM Privilege Escalation · AttachUserPolicy granted AdministratorAccess to · principalsvc-build-botCritical
13:31:48T1110.003Password Spray Detected · 412 failed logins across accounts38 from a single source · src185.143.x.xHigh
13:14:55T1059.001Suspicious PowerShell Execution · Base64 encoded command launched by · processwinword.exe · host=corp-fin-ws-04High
12:58:32T1071.001C2 Beacon Pattern · Periodic HTTPS callouts to domaincdn-static-asset.xyz every 58sCritical
12:41:19T1027Obfuscated Payload Uploaded · High-entropy archive dropped to path/tmp/.cache/.sysMedium
12:27:04T1486Mass File Modification · 2,184 files renamed with extension ext.locked within 90sCritical
12:09:51T1190Public-Facing Service Exploit · CVE-2024-1086 exploitation attempt on serviceedge-gateway-03High
11:54:38T1003.001LSASS Memory Dump · comsvcs.dll MiniDump invoked on hostfin-dc-01Critical
11:37:12T1219Remote Access Tool Launched · AnyDesk.exe spawned from user temp directory · userjdoeHigh
11:21:48T1018Internal Network Discovery · nltest enumerated 47 domain controllers in 8sMedium
10:58:22T1547.001Registry Run Key Modified · Persistence written to keyHKCU\...\Run\UpdateSvcHigh
10:42:09T1567.002Exfil via Cloud Storage · 1.2 GB pushed to destinationtransfer.sh over 6 minCritical
10:26:51T1136.001Local Account Created · net user added svc-helper to local admins on hostcorp-ws-22High
10:11:34T1083File and Directory Discovery · Recursive listing of pathC:\Users\PublicMedium
09:54:17T1055Process Injection Detected · rundll32.exe injected into explorer.exeCritical
09:38:02T1574.002DLL Side-Loading · Unsigned version.dll loaded next to trusted binaryHigh
09:21:46T1496Cryptominer Activity · Sustained 96% CPU on hostrender-node-07 beaconing to known mining poolMedium
AletheiaAletheia

Welcome Back

Sign In to your Aletheia account

Forgot your password?
or

Protected by Aletheia Security. By signing in, you agree to our
Terms of Service

Don't have an account? Sign up