Incident Management

Track, investigate, and resolve security incidents

Open Critical

3

Investigating

3

SLA Breached

1

Resolved Today

3

Incident IDTitleSeverityStatusAssigneeAffected AssetsFirst SeenMTTDEventsMITRE TacticSLAActions
INC-2026-0041

Active C2 Beacon — Workstation HR-14

Critical
Investigating
SA
Selin
workstation-hr-14core-dns-01
07:04:122.3 min847
T1071Command & Control
✓ On time
View details
Mark resolved
INC-2026-0040

SSH Brute Force — auth-server-01 (1,247 attempts)

Critical
Contained
MY
Mehmet
auth-server-01
06:48:211.8 min1,247
T1110Credential Access
✓ On time
View details
Mark resolved
INC-2026-0039

Lateral Movement Detected — Dev Subnet

Critical
Investigating
AK
Ayşe
workstation-dev-07db-server-02+1
06:31:094.1 min312
T1021Lateral Movement
Breached
View details
Mark resolved
INC-2026-0038

DNS Tunneling — Data Exfiltration Suspected

High
Investigating
SA
Selin
core-dns-0110.0.1.5
05:54:336.2 min2,341
T1048Exfiltration
✓ On time
View details
Mark resolved
INC-2026-0037

RDP Brute Force — rdp-gateway-01

High
Contained
MY
Mehmet
rdp-gateway-01
04:12:083.4 min534
T1133Initial Access
✓ On time
View details
Mark resolved
INC-2026-0036

SQL Injection Campaign — webapp-prod-02

High
Resolved
AK
Ayşe
webapp-prod-02db-server-02
2026-03-15 22:34:175.7 min893
T1190Initial Access
✓ On time
View details
Mark resolved
INC-2026-0035

Privilege Escalation — mail-server-01

Medium
Resolved
SA
Selin
mail-server-01
2026-03-15 18:11:448.3 min47
T1068Privilege Escalation
✓ On time
View details
Mark resolved
INC-2026-0034

DoS Attack — External-Facing Load Balancer

Medium
Closed
MY
Mehmet
lb-ext-01dmz-fw-01
2026-03-15 14:22:3111.2 min15,834
T1499Impact
✓ On time
View details
Mark resolved
8 incidents matching filters