SYNOTI v1.11.33
AR
Alerts / 24h
6,842
312 critical · 412 high
Level 12+
12
critical severity
Level 7+
147
high severity
Active Responses
1,289
auto-triggered
Rule Groups
22
matched

Event Stream

TimeAgentRuleLevelDescriptionGroup
18:42:11www-038660512Critical CVE-2026-4432 — RCE in www-03vulnerability-detector
18:41:58www-0310023File added: /var/www/backdoor.phpsyscheck
18:40:44ws-0555037Rootkit detected — /dev/sda1 hiddenrootcheck
18:39:21ws-0559003Active response started: firewall-dropactive-response
18:38:07proxy-025775sshd: 5 failed auth from 203.0.113.45syslog
18:35:52mysql-028076gpgcheck disabled in yum.confaudit
18:33:40mail-018710310Suspicious SMB share access — ADMIN$windows
18:31:18k8s-02601167Docker: privileged container starteddocker
18:28:55app-06866049CVE-2026-1122 — kernel exploit attemptvulnerability-detector
18:26:33app-065144Group added: adm / dev-ssh-userssyscheck

Event Volume / 24h

Top Modules (24h)

View all
FIM
1204%
Syslog
3412%
Active Response
1289%
Cloud
318%
Vuln Detector
412%

Recent Activity

View all
Ransomware behavior blocked on mail-01 CRITICAL
Playbook PB-041 auto-contained host · Ryuk TTPs matched
2m
SSH brute force from 203.0.113.42 HIGH
42 failed logins in 60s · source IP blocked
9m
Threat hunt matched T1059.001 on www-02
PowerShell obfuscation · confidence 0.91
14m
SCA scan completed on 128 hosts
98.2% compliance · 11 benchmarks passed
23m
Firewall rule 'BLK-3321' propagated to 14 nodes
0.4s propagation · geo-blocked 12 CIDRs
31m
Sandbox verdict — 'invoice_9921.exe' malicious
Heuristic score 96 · family 'Emotet'
44m