Initial Access
Execution
Persistence
Priv. Esc
Cred. Access
Discovery
Lateral Move
Collection
C2
Exfiltration
Correlated Alerts & Timeline
Entity Graph 3-hop · 7 entities
● host ● user ● ip ● malicious
✨ AI Investigation Assistant
Attack story. An attacker gained execution on WS-042 via malicious PowerShell, dumped credentials (LSASS), then used j.okafor's creds to move laterally over SMB to 3 hosts while beaconing to 185.x.
Recommended. Isolate WS-042, revoke j.okafor tokens, block 185.x at the firewall.
▶ Run playbookAsk follow-up…