Overview
File verdicts
Activity · last 14 days
Open cases
| severity | case | items | assignee |
|---|---|---|---|
| Loading… | |||
Open alerts
| severity | value | why | seen |
|---|---|---|---|
| Loading… | |||
Techniques seen · MITRE ATT&CK
Pulled together from what static analysis inferred, what the detection rules matched and what the sandbox watched happen. A technique reported by more than one of those was both inferred from the file and observed running, which is a stronger claim than either on its own.
Feeds and rulesets — the corpus this installation matches against, and how current it is
Threat feeds — indicators
| feed | indicators | last sync | state | licence |
|---|---|---|---|---|
| — | ||||
Detection rule feeds — curated YARA rulesets
| ruleset | rules | last import | state | licence |
|---|---|---|---|---|
| — | ||||
Imported as one platform-provided rule per package, so cross-rule references and import statements survive. A failed import changes nothing — the previous ruleset stays in place rather than leaving the installation undefended.
Most-seen indicators
| type | value | sightings | last seen |
|---|---|---|---|
| Loading… | |||
Search
Files
More filters
Indicators
More filters
Sandbox
Cases
Campaigns
Grouped from your own corpus — by import table, byte-level similarity, or shared infrastructure that is rare in your files. Not how common a sample is in the world, but how many times something like it has arrived here. Rebuilt nightly.
Watchlist
Reported messages
Detection rules
Who has access
Visible to every member, not only admins — this list is how you verify that no unexpected account, including a vendor support account, has access.
Members — everyone who can reach this organisation's data
Visible to every member, not just admins: this list is how you verify that no unexpected account — including a vendor support account — has access.
| user | role | status | |
|---|---|---|---|
| — | |||
Your organisation — the tenant this session is acting in
Audit log — who did what, and when
| time | user | action | target |
|---|---|---|---|
| — | |||
Usage
What this organisation used, month by month. Recorded as things happen rather than counted afterwards, so a retention policy that removes the files does not change what the month says.