Product Tour · XDR

See the XDR console

Premium security — everything in SOC, plus correlation, behaviour analytics and hunting.

SOCXDRNOC

About this tour

VultSight XDR includes everything in SOC and adds the analyst-grade layer: cross-domain incident correlation, UEBA and threat hunting. The three screens below show that layer.

01

Investigation Workbench

Related signals correlated into one incident, with an AI-written attack story.

Entity graphKill chainAI assistant
VultSight Console · XDR
INC-20260617-0007 · Multi-stage intrusion
Investigation Workbench · 6 correlated alerts
CriticalContaining
Initial Access
Execution
Persistence
Priv. Esc
Cred. Access
Discovery
Lateral Move
Collection
C2
Exfiltration
Correlated Alerts & Timeline
Suspicious PowerShell
WS-042 · T1059.001
09:41
Credential dumping
LSASS access · T1003
09:43
C2 Beaconing
10.0.1.42 → 185.x · T1071
09:48
SMB lateral movement
→ 3 hosts · T1021.002
09:55
Impossible travel
j.okafor · IN→NL
10:02
Entity Graph 3-hop · 7 entities
WS-042 j.okafor 10.0.1.42 DC-01 185.x C2 SRV-09 mimi.exe
● host  ● user  ● ip  ● malicious
✨ AI Investigation Assistant
Attack story. An attacker gained execution on WS-042 via malicious PowerShell, dumped credentials (LSASS), then used j.okafor's creds to move laterally over SMB to 3 hosts while beaconing to 185.x.
Recommended. Isolate WS-042, revoke j.okafor tokens, block 185.x at the firewall.
▶ Run playbookAsk follow-up…
02 · Investigation Workbench
02

UEBA & Risk Scoring

Behavioural baselines and a 0–100 risk score that catch what rules miss.

Entity riskBaselinesAnomalies
VultSight Console · XDR
User & Entity Behavior Analytics
Behavioral baselines · anomaly detection
Baselines updated 4m ago
Entities Monitored
1,284
users · hosts · ip · svc
Critical Risk (≥80)
7
▲ 2 · 24h
High Risk (≥60)
23
▲ 5
Anomalies · 24h
48
▼ 9
Top Risk Entities composite risk · 0–100
EntityTypeRiskTrendTop driver
WS-042Host
94
Cred. dumping
j.okaforUser
88
Impossible travel
10.0.1.42IP
82
C2 traffic
svc-backupService
67
Off-hours access
a.mensahUser
58
Data volume
SRV-09Host
44
New process
Risk Distribution
1,284entities
Critical7
High23
Medium156
Low1,098
Anomaly Trend · 7d
Peer-group baselines · sigma deviation
04 · UEBA & Risk Scoring
03

Threat Hunting

Hypothesis-driven, retroactive IOC sweeps across history.

IOC sweepsTTP huntsPromote to rule
VultSight Console · XDR
Threat Hunting
Hypothesis-driven · retroactive IOC sweeps
3 running
Hunts
HuntTypeStatusHits
LOLBin executionTTPRunning7
CISA KEV · CVE-2026-… IOCRunning2
DNS tunneling entropyStatRunning0
Impossible travel · 90dRuleDone4
C2 beacon periodicityTTPScheduled
Sigma · new persistenceSigmaDone1
Retroactive sweep across 90 days of events
Active hunt · LOLBin execution MITRE T1218
Hypothesis. Adversary is living off the land — abusing signed Windows binaries (rundll32, mshta, regsvr32) to execute payloads and evade signatures.
IOCs / patterns swept
rundll32.exemshta.exeregsvr32 /s /ucertutil -urlcache
Matches · 7
TimeHostSignalUser
09:41WS-042rundll32 → payload.dllj.okafor
10:12WS-118mshta http://185.xa.mensah
10:26SRV-09regsvr32 /s /u scrobjsvc-app
11:03WS-051certutil -urlcacher.silva
▶ Promote to detection ruleOpen in Investigation
Threat Hunting