Vault SOC

Investigations (AI)

Your approved AI model in Halcyon's AWS GovCloud investigates every alert. Median time to verdict 47s.

Open (11)

XDR-4821Critical07:24
Suspected Cobalt Strike beacon on ENG-WS-114 (CUI enclave)

A macro-enabled attachment "Updated PO 44817.docm" from a look-alike domain spawned encoded PowerShell, which injected into rundll32.exe and began beaconing to 185.220.101.47:443 every 60s with 10% jitter. The host sits in the CUI enclave VLAN. Two other hosts attempted the same destination and were blocked by Advanced Threat Prevention.

True Positive94%Awaiting approval
ENTRA-RS-338High07:08
Impossible travel sign-in from Lagos for m.alvarez

Lagos sign-in 9 minutes after Phoenix. Conditional Access blocked legacy auth, but 1 of 5 MFA pushes was approved. External inbox forwarding discovered; Prisma Access confirms no Lagos VPN. Entra risk: High.

True Positive88%Awaiting approval
SCM-TP-2290High06:49
Outbound C2 attempts to 185.220.101.47 blocked by Advanced Threat Prevention

Threat ID 86xxx (Cobalt Strike Malleable C2) reset-both on HQ-FW-01 and Prisma Access MU. Linked to XDR-4821.

True Positive91%Contained
XDR-4817High04:24
Credential dumping attempt – lsass access blocked by XDR agent

Process comsvcs.dll MiniDump against lsass.exe blocked by Credential Gathering Protection. Process killed automatically under policy rule CP-07.

True Positive90%Contained
MDO-1177High02:14
WildFire malicious verdict on email attachment – quarantined

Invoice_0921.iso flagged malicious by Advanced WildFire. Messages soft-deleted from 3 mailboxes under rule CP-11.

True Positive97%Contained
SCM-DNS-5512Critical07:27
Advanced DNS Security: DNS tunneling from ERP server

High-entropy subdomains of newly registered erp-sync-check[.]net from HP-ERP-01. DNS Security sinkhole already applied; domain blocked automatically via SCM EDL. Server isolation requires explicit approval under CP-02.

True Positive96%Awaiting approval
ENTRA-AP-092Medium07:21
Suspicious OAuth app consent in Entra ("PDF Toolkit Pro")

User consented to multi-tenant app requesting Mail.Read and offline_access. Publisher unverified.

Needs Review66%AI investigating
PUR-DLP-0912High07:16
Purview DLP: CUI drawing sent to personal Gmail

Machinist r.patel sent HP-7731-RevC.dwg, sensitivity label CUI//SP-CTI, to personal Gmail. Exchange trace confirms delivery; SCM logs show personal webmail access. Likely accidental, but CUI impact needs customer review. Do not automatically start a DFARS clock.

Needs Review78%Awaiting approval
XDR-4799High19:30
Anomalous RDP from HP-ERP-01 to HP-DC-02

Interactive RDP using a service account outside its baseline. Unit 42 engaged for scoping (6 hrs).

Needs Review74%Escalated to Unit 42
SCM-WF-772Medium09:50
WildFire malicious verdict – download blocked at HQ-FW-01

Drive-by download blocked inline; no execution on endpoint.

True Positive96%Contained
MDO-1178Medium07:18
Look-alike domain halcyon-precision.co registered

Newly registered domain with MX records; related to update-po-portal[.]com infrastructure.

Needs Review70%New

Closed with evidence (14)

XDR-4820Low05:55
PowerShell download cradle – IT admin script, benign

IEX download of an internal Intune remediation script from an approved repository. Matched change ticket CHG-2214.

Benign98%Resolved
PA-BF-1440Medium05:20
Brute force on VPN portal – blocked by Prisma Access, benign

1,912 failed auths from 44 IPs; no successes. All sources on known password-spray lists; blocked by default policy.

Benign96%Resolved
XDR-4815Low02:30
Unsigned binary executed from Downloads – SOLIDWORKS plugin

Hash prevalence 14 hosts, WildFire benign, vendor confirmed.

Benign95%Resolved
SCM-URL-883Low01:50
Advanced URL Filtering: newly registered domain accessed

Domain belongs to a supplier's new portal; DNS and certificate lineage checked.

Benign93%Resolved
MDO-1176Medium00:40
Credential phishing link clicked – Safe Links blocked

Safe Links time-of-click block. No credential submission observed in Entra sign-in logs.

True Positive89%Resolved
ENTRA-RS-337Low22:50
Risky sign-in: unfamiliar location (Denver) – traveling user

Compliant Intune device, MFA satisfied, travel on calendar.

Benign92%Resolved
XDR-4812Medium21:20
certutil downloading file on HP-ERP-01

ERP vendor patch script; signed payload, matched maintenance window.

Benign87%Resolved
SCM-TP-2288Low18:30
Port scan from guest Wi-Fi blocked by zone protection

Guest device scanning; zone isolation held.

Benign97%Resolved
DLP-0456Low17:30
Purview DLP: ITAR keyword in Teams chat – internal only

Internal participants only, all U.S. persons per HR attribute.

Benign90%Resolved
MDO-1175Low16:30
Bulk spam campaign – ZAP removed 41 messages

Zero-hour auto purge succeeded.

Benign99%Resolved
XDR-4809Medium14:50
Ransomware behavioural rule – Veeam backup job

Scheduled Veeam encryption job; parent process and schedule matched.

Benign95%Resolved
PA-DNS-219Low13:30
DGA-like domain lookups from mobile user

Ad-tech CDN with randomised subdomains.

Benign88%Resolved
ENTRA-PIM-045Medium12:20
Global Administrator activated outside change window

PIM activation with justification; confirmed by IT manager via Teams.

Benign91%Resolved
XDR-4806Low10:40
Agent disconnected > 7 days – ENG-WS-019

Laptop in repair depot per asset system.

Benign99%Resolved