Product Tour
Investigation — Full Attack Chain in Minutes
Step 3 of 8
Case cas_00142 — Account Compromise: root
Investigation complete · Attack chain reconstructed · 4 MITRE ATT&CK techniques mapped
Reconnaissance: AWS describe-instances called from unfamiliar IP
203.0.113.5 called DescribeInstances, DescribeSecurityGroups across 4 regions
Initial Access: AWS Console login as root, no MFA, new geolocation
Login from UA/Kyiv; IP reputation -85; no prior logins from this country
Persistence: New IAM admin user created ([email protected])
CreateUser + AttachUserPolicy (AdministratorAccess) in 43 seconds
Exfiltration: 14 GB GetObject from S3 bucket acme-pii-backup-prod
14,211 objects accessed over 8 minutes from newly created access key
Automatic attack chain reconstruction
The Investigate Agent correlates events across all connected sources to reconstruct the complete attack sequence — from initial access through persistence and exfiltration — without manual pivoting.
MITRE ATT&CK auto-mapping
Each observed TTP is automatically mapped to the MITRE ATT&CK technique, with the relevant events as supporting evidence. Export as a MITRE Navigator layer.
Full evidence audit trail
Every data point the agent accessed is logged — which entity it queried, which events it retrieved, which TI lookups it ran — creating a defensible, reproducible investigation record.