SOC operations
Live analyst board.
Triage queue, on-shift load, and SLA performance — synchronized across all regional pods.
Open alerts
Auto-resolved (24h)
Median triage time
Analysts on shift
Queue
12Unusual OAuth scope grant
mediumALR-91212OktaCore
Bulk download · sharepoint
lowALR-91210M365
Stale credential reuse
lowALR-91207IAM
Triage
7Process hollowing on fin-db-prod-04
criticalALR-91204CrowdLens
Egress to unsanctioned ASN
highALR-91197GuardWatch
In Progress
9Impossible travel · svc-account-build
highALR-91182OktaCore
Privileged exec in k8s-payments
mediumALR-91175Lens-Q
DNS tunneling pattern · edge-pop-sgp
mediumALR-91168NetScope
Escalated
3Token theft · Salesforce surface
criticalINC-4471IR Bridge
Active alerts
| ID | Severity | Rule | Asset | Source | Age | Owner |
|---|---|---|---|---|---|---|
| ALR-91204 | critical | Process Hollowing detected | fin-db-prod-04 | EDR · CrowdLens | 2m | L. Okonkwo |
| ALR-91197 | high | Egress to unsanctioned ASN | vpc-eu-w-2 | Cloud · GuardWatch | 7m | Unassigned |
| ALR-91182 | high | Impossible travel · 4 hops | svc-account-build | Identity · OktaCore | 12m | K. Marchetti |
| ALR-91175 | medium | Unusual privileged exec | k8s-payments | SIEM · Lens-Q | 18m | L. Okonkwo |
| ALR-91168 | medium | DNS tunneling pattern | edge-pop-sgp | Network · NetScope | 26m | S. Berenson |
| ALR-91161 | low | Lookalike domain spoof | exec-mailbox | Email · Inkwell | 41m | K. Marchetti |
On-shift roster
- LO
L. Okonkwo
Tier-3 Hunter
Load7 - KM
K. Marchetti
Tier-2 Analyst
Load4 - SB
S. Berenson
Tier-2 Analyst
Load5 - RH
R. Hayashi
Tier-1 Triage
Load9 - PD
P. Devereux
IR Lead
Load2
P1 SLA
98.4%
P2 SLA
94.7%
Response performance