Overview Stats
Total Number of Alerts Generated
7.2k
Number of Alerts That Made it to a Case
7.1k
Total Case Count
3.0k
Closed Case Count
2.9k
Open Cases by Priority
High
Critical
Low
114

Total

Cases by Status
New
Open
Resolved
Closed
2,991

Total

Cases by Type
3.0k3.0k2.0k2.0k1.0k1.0k00 ThreatLink ThreatLink ThreatLinkMalware ThreatLinkMalware Log4J Log4J Metaflow Metaflow Impossible Travel Impossible Travel
2,991

Total

Open Cases
Case_ID
priority
status
Minutes_Since_Created
CaseType
title
CriticalNew10792Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
CriticalResolved118ThreatLinkMalware10.10.162.22 C2++Slingshot+APT Command and Control Activity
CriticalOpen94ThreatLinkMalwareSlingshot+APT execution detected on owiddison2d_wrkstn
CriticalResolved64ThreatLinkMalware10.10.160.37 C2++Slingshot+APT Command and Control Activity
CriticalResolved43ThreatLinkMalware10.10.160.47 C2++Slingshot+APT Command and Control Activity
CriticalNew19ThreatLinkMalwareSlingshot+APT execution detected on jscandrett5h_lptp
CriticalNew16ThreatLinkMalware10.10.160.60 C2++Slingshot+APT Command and Control Activity
HighNew11152Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew11032Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew10912Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew10735MetaflowMetadata case for source
HighNew10672Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew10552Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew10432Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew10312Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew10192Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew10072Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew9952Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew9832Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew9712Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew9592Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew9472Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew9352Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew9295MetaflowMetadata case for source
HighNew9232Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew9112Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew8992Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew8872Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew8752Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew8632Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew8512Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew8392Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew8272Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew8266Impossible Traveljcourtint@vital.com is showing impossible travel
HighNew8152Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew8032Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew7912Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew7855MetaflowMetadata case for source
HighNew7792Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew7672Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew7552Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew7432Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew7312Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew7192Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew7072Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew6952Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew6832Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew6712Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew6592Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew6472Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew6415MetaflowMetadata case for source
HighNew6352Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew6232Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew6112Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew5992Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew5872Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew5752Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew5632Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew5512Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew5392Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew5272Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew5152Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew5032Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew4975MetaflowMetadata case for source
HighNew4912Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew4792Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew4672Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew4552Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew4432Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew4312Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew4192Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew4072Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew3952Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew3832Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew3712Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew3592Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew3535MetaflowMetadata case for source
HighNew3472Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew3352Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew3232Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew3112Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew2992Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew2872Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew2752Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew2632Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew2512Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew2392Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew2272Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew2152Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew2095MetaflowMetadata case for source
HighNew2032Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew1912Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew1792Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew1672Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew1552Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew1432Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew1312Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew1192Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew1072Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
HighNew952Log4JLog4Shell - CVE-2021-44228 - Prod_Websrv_02
Top 10 Alerts
alert_name
alert_count
SecIntSimultaneouslyLoginbyIP900
SecIntSimultaneouslyLoginbyIPv2800
SecOpsLocalUserCreation_clonedv2452
SecOpsResetPasswordAttempt433
SecOpsLocalUserCreation431
SecOpsPossibleDnsEncodingQuery424
Demo_SlingshotAPT_EDRAlert345
SecIntSimultaneouslyLoginbyUser322
Demo_SlingshotAPT_IDSAlert320
Malicious_IP257
Top 10 Alerts in Cases
alert_name
case_count
total_time_seen_in_a_case
SecOpsResetPasswordAttempt439439
SecOpsLocalUserCreation435435
SecOpsPossibleDnsEncodingQuery331427
Demo_SlingshotAPT_IDSAlert297325
Demo_SlingshotAPT_EDRAlert270350
SecOpsLoginFailCombinedSuccessed199219
SecOpsFailLogOn187202
SecOpsCDHuntFWSrcIpIsPossibleIoc144168
Malicious_IP105259
SecOpsLocalUserCreation_clonedv299457
MTTR Metrics
chart_name
value
StatusClosed
Closed Count2877
Median Minutes to Close95.53
Average Minutes to Close104.05
Standard Deviation of Average Minutes to Close 47.03
Fastest Case Closure30.47
Slowest Case Closure405.77
80% of Cases closed in less than:138.48
95% of Cases closed in less than:189.75
Case Metrics by Status
status
avg_Time_In_Status
min_Time_In_Status
max_Time_In_Status
New5504.1116.2711152.82
Medium115.2412.53296.5
High134.820.013278.67
Low7.425.978.87
Critical5.525.525.52
Open38.5710.24221.61
Closed0.320.0149.98
Resolved0.760.0199.97
Cases Created by Date
60060040040020020000 2024/07/15 2024/07/15 2024/07/16 2024/07/16 2024/07/17 2024/07/17 2024/07/18 2024/07/18 2024/07/19 2024/07/19 2024/07/20 2024/07/20 2024/07/21 2024/07/21 2024/07/22 2024/07/22
2,991

Total

MTTR
104.05
minutes