🔔
JM
Recent Notifications
New Escalated Case
TKT-0044 SLA breach imminent.
System Update
Platform maintenance scheduled for 02:00 AM.
Josh Mercer
SOC Analyst II
  • Edit Profile
  • Preferences
  • Dark Mode

  • Sign Out

Security Operations Dashboard

Mean Time to Detect (MTTD)
4m 12s
Mean Time to Respond (MTTR)
18m 45s
SLA Compliance
98.2%
[Incident Volume Chart Visualization]

My Assigned Cases (12)

TKT-0042: PDF flagged by user Active - 14 mins ago
TKT-0041: Geo-targeted phishing reported Active - 45 mins ago
TKT-0018: Weekly firewall config review On Hold - 2 days ago

Knowledge Base & Runbooks

SOP-Phishing-01

Handling reported suspicious emails, sandbox isolation, and URL analysis.

SOP-Malware-04

Isolating infected endpoints via CrowdStrike and retrieving memory dumps.

Generate Report

Case Queue

Live
Active Cases
24
Needs Review
8
Critical Priority
1
Unassigned
5
My Assigned Cases 12
All Open Cases 24
Needs Triage 5
Escalated 2
Case ID
Priority
Category
Subject
Status
Assignee
Created
TKT-0042
High
Suspicious Attachment
PDF flagged by user — sent to multiple employees
New
J. Mercer
8:31 AM
Reported by
M. Chen
Source
User report
Category
Suspicious Attachment
Affected Users
6 recipients (Finance dept.)
Description

User flagged a PDF received via external email. Same file sent to at least 6 employees in Finance. Sender domain is unfamiliar. PDF filename matches a known social-engineering pattern. No sandbox analysis yet.

📄
poc_malware.pdf 842 KB · Received 8:14 AM · External sender
TKT-0043
Med
Suspicious Document
Invoice.docx shared via Dropbox — macro warning
Needs Review
J. Mercer
7:55 AM
Reported by
Automated — DLP scan
Source
Dropbox file share
Category
Suspicious Document / Macro
Shared by
M. Chen
Description

DLP system flagged a Dropbox shared document containing embedded macros. File was shared internally by M. Chen, originally received from an external vendor contact. Macros not yet inspected. File has been quarantined pending review.

📝
Agreement.FINAL.docm 1.2 MB · Shared via Dropbox · Contains macros
TKT-0044
High
Malicious Attachment
Email with ZIP and EXE attachments
New
Unassigned
7:42 AM
Reported by
Email gateway — auto-flag
Source
Inbound email
Category
Malicious Attachment
Recipient
R. Patel
Description

Email gateway flagged inbound message to R. Patel containing a ZIP archive and a standalone EXE. Sender claims to be a software vendor providing an "urgent security update." ZIP contains a VBS script alongside the executable. Held in quarantine.

📦
svc_update_v4.2.zip 3.8 MB · Contains: svc_update.exe, install.vbs
TKT-0045
Crit
Suspicious Script
Suspicious PowerShell script from Endpoint-07
Needs Review
J. Mercer
7:18 AM
Reported by
EDR alert — CrowdStrike
Source
Endpoint detection
Category
Suspicious Script Execution
Endpoint
Endpoint-07 (WKS-FINANCE-03)
Description

EDR flagged a PowerShell process on Endpoint-07 executing an obfuscated script. Process spawned from an unexpected parent (explorer.exe → powershell.exe). Script attempts to download a secondary payload from an external IP. Endpoint isolated pending analysis. User account: svc_backup.

svc_update.ps1 4.1 KB · Extracted from Endpoint-07 · Obfuscated