🔍
ROLE: ADMIN_SOC_LEAD

Security Operations Center (Overview)

Hybrid workspace consolidating Sentinel analytics metrics and Google Chronicle entity tracking.

Ingestion Rate
14,852 EPS▲ +12.4%
Active Incidents
6 Open▼ -18.2%
Monitored Assets
1,489 Active▲ +2.1%
Consensus Health
100% Stable▲ 0.0%

Geovelocity Impossible Travel Visualizer

Real-time mapping of concurrent geolocation SSO credentials requests

Boston, US
(User Host)
Impossible Travel
Tokyo, JP
(Unauthorized login)

Telemetry Data Marts

Windows Event MartActive Directory logs
STABLE
Linux Syslog & eBPFSyslog kernel traces
STABLE
Firewall Flow MartIngestion flow records
STABLE
Identity Governance MartMFA, Saviynt log traces
ALERT

Actionable Security Alerts Grid

Correlated security events mapped to MITRE TTPs and inline containment triggers

Threat IDIncident DetailsMITRE TTPExposure Entity TargetRaw Syslog PreviewSeverityStatusActions
SEC-902
Account Takeover (ATO) - Impossible Travel Anomaly
Source: Tokyo, JP & Boston, US
T1078KVM:4a12c984:AppInstance-Bsshd: Accepted publickey for sridhargs from 185.220.101.5CRITICALACTIVE
SEC-903
Active Directory Password Spray Attack
Source: 10.101.40.2 (Local vNIC)
T1110ESXi:f0f1882a:AppInstance-Ckrb5: Kerberos login failure for user admin - Preauth failedHIGHACTIVE
SEC-904
Container Privilege Elevation eBPF Alert
Source: Container ID: c52ea7b
T1548KVM:4a12c984:AppInstance-Aauditd: execve command: sudo rm -rf /etc/hosts (uid=1001)HIGHACTIVE
SEC-905
Tandem Legacy System SMF Journal Level Override
Source: Tandem LegacyTel Bridge
T1562ZOS:LPAR2:RACF_MGRLegacyTel: RACF Audit override level set to: NONECRITICALACTIVE