SYNOTI v1.11.33
AR
Active Detections
148
12 in the last 24h
Critical Threats
12
2 new since yesterday
Auto-Contained
62%
of incidents · PB-041
IOCs Enriched / 24h
1.2M
8% coverage growth
Blocked by Reputation
9,847
9% automatic blocks

Detections by Source

Threat Score Distribution

Top MITRE Techniques

Active Detections

DetectionSeveritySourceStatusAge
SSH brute force from 203.0.113.45 — ws-05HighWazuh IDS/IPSOpen12m
Ransomware behavior on mail-01CriticalWazuh EDRContained2m
DNS tunneling — exfil to 198.51.100.34CriticalWazuh XDRInvestigating1h 20m
PowerShell encoded command — ws-05HighWazuh EDROpen41m
Office macro execution — HR-2026.xlsmHighMail Gateway (Postfix)Open3h 30m
Phishing campaign — finance deptMediumMail Gateway (Postfix)Investigating1h
SMB lateral movement — wavesHighWazuh IDS/IPSInvestigating9h
Policy violation — USB usageLowWazuh XDRResolved3h

Detection Rules — Top Hit

RuleSeverityHits / 24hStatus
Ransomware behaviorCRITICAL42Active
DNS tunnelingCRITICAL18Active
SSH brute forceHIGH156Active
PowerShell encodedHIGH33Active
Office macro execMEDIUM61Draft

Triage Rules

RuleMatchActionStatus
critical-to-socseverity=criticalAssign SOC lead + ChatOpsActive
auto-contain-ransomrule=ransomware*Run PB-041 auto-containActive
phish-quarantinesource=email & phish*Quarantine + notifyActive
test-noisesource=~test.*DropPaused

Recent Activity

View all
Incident INC-32464 opened — high CPU on app-02 CRITICAL
Auto-remediation playbook PB-031 triggered
1m
Worker k8s-07 at 91% load
Auto-scaled +2 workers to queue 'scan'
6m
Backup completed — 1.4 TB in 8m 12s
Snapshot verified · retention 30 days
18m
Sync task 's3-archive' finished
2,104 objects · 0 conflicts
27m
phy-12 added to monitoring
18 agents enrolled · health 100
39m
Task T-9912 'patch-cron' succeeded
Ran on 96 hosts · 0 errors
52m