Security Operations Dashboard
My Assigned Cases (12)
Knowledge Base & Runbooks
SOP-Phishing-01
Handling reported suspicious emails, sandbox isolation, and URL analysis.
SOP-Malware-04
Isolating infected endpoints via CrowdStrike and retrieving memory dumps.
Generate Report
Case Queue
LiveUser flagged a PDF received via external email. Same file sent to at least 6 employees in Finance. Sender domain is unfamiliar. PDF filename matches a known social-engineering pattern. No sandbox analysis yet.
DLP system flagged a Dropbox shared document containing embedded macros. File was shared internally by M. Chen, originally received from an external vendor contact. Macros not yet inspected. File has been quarantined pending review.
Email gateway flagged inbound message to R. Patel containing a ZIP archive and a standalone EXE. Sender claims to be a software vendor providing an "urgent security update." ZIP contains a VBS script alongside the executable. Held in quarantine.
EDR flagged a PowerShell process on Endpoint-07 executing an obfuscated script. Process spawned from an unexpected parent (explorer.exe → powershell.exe). Script attempts to download a secondary payload from an external IP. Endpoint isolated pending analysis. User account: svc_backup.