Activity Feed
All incident events across active sessions
12 accounts show success-after-failure pattern consistent with credential stuffing from HaveIBeenPwned corpus.
Confirmed phishing email received at 08:42 UTC. Attachment analysis in progress.
Auth failure spike detected: 4,200 failures in 30 min — 8x baseline
Anomalous AWS ListBuckets call from ci-deploy role — 12 minutes after credential exfil. Recommend immediate credential rotation.
Alert escalated to SEV-1 by detection rules
EDR alert: LSASS dump detected on eng-mbp-msilva.local
Incident resolved. Postmortem scheduled.
All sessions terminated. Two API tokens identified as attacker-created — pending deletion.
Session token reuse pattern confirmed. New device fingerprint, no MFA challenge logged. Recommend immediate session termination.
Impossible travel alert: Paris (09:14 UTC) → Lagos (18:22 UTC) — same account, 9h apart
Legal review complete. Customer notifications sent. DPA filed.
7 external IPs accessed 43 objects during the 43-minute exposure window. Estimated 1,400 records. GDPR Article 33 likely triggered (72h notification window).
Public access block re-enabled. Bucket secured.
S3 public access alert: incidentconnect-customer-exports bucket made public