Investigations (AI)
Your approved AI model in Halcyon's AWS GovCloud investigates every alert. Median time to verdict 47s.
Open (11)
A macro-enabled attachment "Updated PO 44817.docm" from a look-alike domain spawned encoded PowerShell, which injected into rundll32.exe and began beaconing to 185.220.101.47:443 every 60s with 10% jitter. The host sits in the CUI enclave VLAN. Two other hosts attempted the same destination and were blocked by Advanced Threat Prevention.
Lagos sign-in 9 minutes after Phoenix. Conditional Access blocked legacy auth, but 1 of 5 MFA pushes was approved. External inbox forwarding discovered; Prisma Access confirms no Lagos VPN. Entra risk: High.
Threat ID 86xxx (Cobalt Strike Malleable C2) reset-both on HQ-FW-01 and Prisma Access MU. Linked to XDR-4821.
Process comsvcs.dll MiniDump against lsass.exe blocked by Credential Gathering Protection. Process killed automatically under policy rule CP-07.
Invoice_0921.iso flagged malicious by Advanced WildFire. Messages soft-deleted from 3 mailboxes under rule CP-11.
High-entropy subdomains of newly registered erp-sync-check[.]net from HP-ERP-01. DNS Security sinkhole already applied; domain blocked automatically via SCM EDL. Server isolation requires explicit approval under CP-02.
User consented to multi-tenant app requesting Mail.Read and offline_access. Publisher unverified.
Machinist r.patel sent HP-7731-RevC.dwg, sensitivity label CUI//SP-CTI, to personal Gmail. Exchange trace confirms delivery; SCM logs show personal webmail access. Likely accidental, but CUI impact needs customer review. Do not automatically start a DFARS clock.
Interactive RDP using a service account outside its baseline. Unit 42 engaged for scoping (6 hrs).
Drive-by download blocked inline; no execution on endpoint.
Newly registered domain with MX records; related to update-po-portal[.]com infrastructure.
Closed with evidence (14)
IEX download of an internal Intune remediation script from an approved repository. Matched change ticket CHG-2214.
1,912 failed auths from 44 IPs; no successes. All sources on known password-spray lists; blocked by default policy.
Hash prevalence 14 hosts, WildFire benign, vendor confirmed.
Domain belongs to a supplier's new portal; DNS and certificate lineage checked.
Safe Links time-of-click block. No credential submission observed in Entra sign-in logs.
Compliant Intune device, MFA satisfied, travel on calendar.
ERP vendor patch script; signed payload, matched maintenance window.
Guest device scanning; zone isolation held.
Internal participants only, all U.S. persons per HR attribute.
Zero-hour auto purge succeeded.
Scheduled Veeam encryption job; parent process and schedule matched.
Ad-tech CDN with randomised subdomains.
PIM activation with justification; confirmed by IT manager via Teams.
Laptop in repair depot per asset system.