KESTREL
Security Operations
/
Last 24 hours
Sensors 18/18
LIVE
KM
K. Mahoe
SOC Analyst II

Notifications

Security Overview

Real-time detection summary across endpoint, network, identity & cloud telemetry · 22 Jun 2026, 08:00 – 12:00 UTC

Event Volume

events / hour · 24h

Alerts by Severity

last 24h

Detections by Tactic

MITRE ATT&CK

Top External Sources

by alert volume

Detection Coverage

analytic health

ATT&CK Coverage — Active Incident

techniques observed in INC-2026-0419

Live Alert Feed

most recent · click a row to investigate
Time (UTC)SeverityDetection SourceDestinationEntityStatus

Alerts

0 detections in the selected window
Severity:
Time (UTC)SeverityDetection SourceDestinationEntityStatus

Incident Response Console

Document case findings and execute response playbooks. Validated actions issue an evidence token.

Threat Intelligence — Indicator Blocklist

Indicators blocked here are pushed to firewall, EDR and DNS sinkhole enforcement.
TypeIndicatorCategoryAddedStatus

Assets

Managed endpoints & servers with current risk score and containment state.
HostAddressRoleOwner RiskState