Alarms
Major events raised by the agents — probing, breaches, lateral movement, denial of service and data exfiltration.
Open · 4
Lateral movement into payments tier
10.4.19.66 → app-tier · svc-payments · detected by Pathfinder
An external adversary established a foothold on wks-2231 and pivoted into the payments service tier within one second — machine-speed lateral movement across a segment boundary.
Autonomous recon sweep on edge gateway
45.148.10.221 → Perimeter · edge-gw-01 · detected by Sentinel-Net
A reasoning adversary is rotating source ports and request timing to map exposed services on edge-gw-01 while staying under rate-limit thresholds.
Volumetric DoS against auth gateway
botnet · 3.2k sources → auth-gw · cluster-a · detected by Sentinel-Net
Connection-attempt rate is 8.4x baseline from a distributed botnet, threatening availability of the authentication gateway.
Pre-exfiltration data staging in warehouse
10.4.19.66 → db-tier · warehouse-2 · detected by Pathfinder
Customer records are being read sequentially and compressed into a temp share — classic staging ahead of exfiltration.
Resolved · 2
Prompt injection against support model
api-gw-east / user field → AI model · support-llm · detected by ModelGuard
A crafted payload attempted to override the system prompt of the customer-support model via a user-controlled field.
Firewall rule tamper auto-reverted
user · ci-runner → network · fw-ruleset · detected by Sentinel-Net
A pipeline commit opened an internal port to the internet; the change was detected and rolled back automatically.