Vault SOC

Morning Brief — Thursday, October 8

Report window 07:30 PT Wed → 07:30 PT Thu

Written by AI SOC · 07:31 PT
Overnight the AI SOC investigated 1,284 alerts across Cortex XDR, Strata and Microsoft 365. 1,271 were closed as benign with evidence. 3 threats were contained automatically under your policy. 3 decisions are waiting for you — the most urgent is a Cobalt Strike-like beacon on ENG-WS-114 in the CUI enclave, delivered by a look-alike purchase-order email. No evidence of data exfiltration was found.
Alerts ingested (24h)
1,284
Investigated
100%
Median time to verdict
47s
Auto-contained
3
Awaiting approval
3
Escalated to humans
1

Alerts per hour · 07:30 Wed → 07:30 Thu PT

Needs your decision (3)

CriticalXDR-4821
Isolate endpoint ENG-WS-114
AI confidence 94% · Cortex XDR
Recommended: Network isolation on ENG-WS-114 (agent 8.4.1)
Open investigation
HighENTRA-RS-338
Revoke sessions for m.alvarez
AI confidence 88% · Entra ID
Recommended: Revoke refresh tokens and active sessions
Open investigation
CriticalSCM-DNS-5512
Isolate ERP server HP-ERP-01
AI confidence 96% · Cortex XDR
Recommended: Server isolation interrupts ERP and machining work orders
Open investigation

Contained overnight

  • 07:28 PTBlock tunneling domain via SCM EDLCP-08 · Block domain · Critical → Auto
  • 02:19 PTSoft-deleted WildFire-malicious attachment from 3 mailboxesCP-11 · Delete email · High → Auto
  • 04:27 PTKilled process and quarantined comsvcs MiniDump tool on HP-FS-01CP-07 · Kill process · High → Auto

Unit 42 retainer · Year 1

67 hrsavailable of 125
Used 18Planned proactive 40Available 67

On call today

  • AI SOC
    24/7 triage and policy-bound response
  • D. Mercer · Vault engineer
    7am–5pm PT, then on call
  • Unit 42 IR
    On standby · retainer active

DFARS 72-hour clock

No reportable incident active. Start the clock from an investigation if CUI impact is suspected.