SYNOTI / XDR
XDR
Extended detection and response — attack surface and detections.
XDR
Alerts
Hygiene Score
78/100
4 this quarter
Exposed Services
3
RDP · SSH · SMTP
Watchlist IOCs
214
8 added / 24h
Detections / 24h
2,340
12% noise reduced
Security Events
| Time | Agent | Rule | Severity | MITRE |
|---|---|---|---|---|
| 18:42:11 | www-03 | 86605 | Critical | T1190 |
| 18:40:44 | ws-05 | 5503 | High | T1014 |
| 18:38:07 | proxy-02 | 577 | Medium | T1110 |
| 18:33:40 | mail-01 | 87103 | High | T1021 |
Detection Sources
MITRE Tactics
Alert Rate
Attack Surface · hygiene 78/100
View allRDP 3389 — 10.20.4.27
96%
SSH 22 — 10.20.4.31
87%
SMTP 25 — mail-proxy-01
64%
HTTPS 443 — www-03
58%
MSSQL 1433 — backup-02
41%
Watchlist
| Indicator | Type | Threat | Seen |
|---|---|---|---|
| 203.0.113.45 | IP | LockBit C2 | 12m |
| e3b0c442…a429 | Hash | Conti sample | 31m |
| payroll-okta[.]com | Domain | Phishing | 1h |
| update-svc[.]net | Domain | Malware dist | 3h |
| 198.51.100.34 | IP | Tor exit | 5h |
Recent Activity
View allRansomware behavior blocked on mail-01 CRITICAL
Playbook PB-041 auto-contained host · Ryuk TTPs matched
SSH brute force from 203.0.113.42 HIGH
42 failed logins in 60s · source IP blocked
Threat hunt matched T1059.001 on www-02
PowerShell obfuscation · confidence 0.91
SCA scan completed on 128 hosts
98.2% compliance · 11 benchmarks passed
Firewall rule 'BLK-3321' propagated to 14 nodes
0.4s propagation · geo-blocked 12 CIDRs
Sandbox verdict — 'invoice_9921.exe' malicious
Heuristic score 96 · family 'Emotet'
