Top Offending IPs
Failed SSH attempts ranked by volumeApache Status Codes
Distribution of HTTP statuses from access logsAlert Severity Mix
Correlation output grouped by severity scoreThreat Intelligence
IOC inventory normalised across AbuseIPDB and AlienVault OTX.
| Indicator | Type | Source | Last Seen | Confidence |
|---|
SSH Login Failures
Failed authentication attempts enriched with usernames and messages.
| Timestamp | IP | User | Message |
|---|
Apache Access Logs
Web requests parsed with HTTP verbs, resources, and response codes.
| Timestamp | IP | Request | Status |
|---|
Alerts
IOC matches correlated across the estate with severity scoring.
| Created | Indicator | Source | Severity | Message |
|---|