00:00:00 UTC
18,420 EPS
SOC ADVISORY
Threat Intel Feed Synced: New Ransomware Indicators (LockBit 3.0) added to SIEM watchlist. EDR Agents Active: 1,240 Endpoint Nodes Online in Corporate LAN & DMZ. Perimeter Firewall: Active DDoS Filtering & BGP Flowspec Enabled. EDR Kernel Intercept: Zero-day memory scraping telemetry streaming at 0.4ms latency.
RAW INGEST STREAM
10
Total Active Alerts
5
Critical Threat Level
0 / 10
Triaged & Contained
100%
Analyst Precision
0
Isolated Endpoint Hosts
SHIFT ALPHA · 06:00–18:00 UTC Enterprise Security Operations 24 analysts · 3 active investigations · Coverage across 6 regions
MTTA (Mean Time to Ack) 01:42 18% vs target
MTTR (Mean Time to Respond) 18:36 Target < 30m
Telemetry Health 99.97% 12 / 12 sources healthy
Assets at Risk 04 Finance ERP · Identity
MAJOR INCIDENT WATCH

LockBit activity targeting Finance ERP

P1 · ACTIVE
Incident INC-2026-08940
Business impact Finance ERP & Payments
Current owner Unassigned
BUSINESS SERVICE HEALTH

Enterprise control plane

96%
Finance & PaymentsDEGRADED
Identity & AccessHEALTHY
Cloud ProductionMONITORING
Industrial OTHEALTHY
SHIFT COMMAND

Alpha response cell

ON DUTY
ARA. RahmanTier 2 AnalystAvailable
MHM. Al-HarbiIncident CommanderStandby
LKL. KhanDFIR SpecialistOn case
Live Global Attack Vectors & C2 Beacons
REALTIME RADAR
SIEM Log Volume (EPS)
18,420 EPS
Severity Breakdown
SIEM Indexer: ONLINE (0.4ms)
Perimeter Firewall: HEALTHY
CrowdStrike Falcon: SYNCED (1,240 Agents)
Splunk SOAR Engine: STANDBY
SOC COMMAND CENTER VIDEO-WALL LIVE WAR ROOM FEED
SLA: 14:59
GLOBAL THREAT RADAR & C2 ARCS RADAR-01
SIEM INGESTION TELEMETRY (EPS) SIEM-STREAM
Ingest Rate: 18,420 EPS
Active P1: 5
Data Lake: HEALTHY
INCIDENT COMMANDER HUD P1 CRITICAL
CASE ID INC-2026-08940
PRIMARY THREAT LockBit 3.0 Ransomware
TARGET ASSET HOST-FINANCE-01 (10.0.4.15)
MITRE ATT&CK T1486 · Data Encrypted for Impact
EDR SENSOR FLEET HEALTH EDR-CLUSTER
Corporate LAN (940 Nodes) ONLINE
Server Farm & DC (180 Nodes) 1 SUSPICIOUS
DMZ Perimeter (60 Nodes) HEALTHY
SCADA / OT Zone (60 Nodes) AIR-GAPPED
REALTIME NETWORK TELEMETRY FEED (PCAP STREAM) PORT-MIRROR-10G
MITRE ATT&CK ACTIVE TACTICS HEATMAP MATRIX-v14
MITRE T1059.001

Select an alert from the SIEM feed

CRITICAL
Target Host: HOST-FINANCE-01
Source IP: 10.0.4.15
Timestamp: 2026-08-13 14:22:01 UTC
User Account: FINANCE\admin_jdoe
SHA256 Hash: 3a8f...b92c
ACTIVE SECURITY INCIDENT
INC-2026-08421 NEW · UNASSIGNED
Business service Finance ERP & Payments Revenue-impacting · Tier 0 asset
Case owner Unassigned SOC Tier 2 · Shift Alpha
Response SLA remaining 14:59 P1 target · 15 minutes
Blast radius 1 endpoint / 1 identity Corporate LAN · Finance
NIST Incident Lifecycle Assign the case to begin investigation
INVESTIGATION CHECKLIST Required evidence for containment approval
0 of 3 evidence items captured
RESPONSE CELL Coordinated stakeholders
SOC Tier 2 DFIR IT Operations Legal & Privacy
INCIDENT TIMELINECommand activity
1 event
SIEM correlation created caseDetection pipeline · just now
Process Execution Tree (EDR Forensics) Click process for deep inspection
Raw Event Payload (JSON)
{}
Threat Intel Reputation Check
Query VirusTotal, AbuseIPDB & AlienVault OTX for IP/Hash reputation.
Ria Cyber AI Threat Copilot AI ANALYST
REALTIME INFERENCE
SOAR Response Playbook Recommendation
Select an alert to view playbook steps...
Analyst Response Decision (SOAR Action)
Analyst Investigation Notes
Analyst Session Audit Log
No triage actions taken in this session yet.
Enterprise Network Topology & EDR Agent Status

SOC INCIDENT RESPONSE BRIEFING

DOCUMENT ID: IR-2026-0813-009 | CONFIDENTIAL · LEVEL 3 CLASSIFICATION
Analyst On Duty:
SOC Tier 2 Analyst
Shift Period:
Shift Alpha (06:00 - 18:00 UTC)
Triage Accuracy:
100%
Hosts Contained:
0

Executive Incident Assessment & Threat Scope

During this operational shift, the Security Operations Center triaged automated telemetry alerts from endpoint EDR, perimeter firewalls, and Windows security event logs. High-confidence indicators were neutralized in accordance with the NIST SP 800-61 Incident Handling Framework.

Executed Response Actions Log

No containment actions recorded in this session yet.

Analyst Incident Notes

No notes entered.

Analyst Mitigation Recommendations

  • Enforce Multi-Factor Authentication (MFA) across all external RDP and VPN entry points.
  • Block PowerShell execution policies via GPO on standard non-admin workstation profiles.
  • Enable Credential Guard to protect LSASS memory against Mimikatz credential dumping.
  • Implement air-gapped immutable backup storage to mitigate ransomware destruction.
  • Deploy Yara rules and network firewall blocks for identified C2 IP indicators.

Falcon Live Response (Remote Shell CLI)

Connected Target: HOST-FINANCE-01 | Session ID: #FLR-9941
CrowdStrike Falcon Live Response v7.1.1
Establishing encrypted SSH channel to target endpoint... [CONNECTED]
Type help for list of EDR investigation commands.
[FALCON-LR@HOST]#
Hotkeys: ps, kill <PID>, isolate, yara-scan

Threat Intelligence Lookup

SOAR Automated Response Execution

EDR Process Inspector

EDR Endpoint Investigator

MITRE ATT&CK Technique

Analyst Hotkey Shortcuts

Key 1 Isolate Host (SOAR Action)
Key 2 Block Source IP (SOAR Action)
Key 3 Kill Process (SOAR Action)
Key 4 Dismiss False Positive
Key 5 Launch Falcon Live Response CLI Terminal
Key W Toggle War Room / Video Wall Mode
/ Key Focus Alert Search Box
Esc Key Close Any Active Modal

SIEM Event Log Detail

{}