Detection thresholds
Tune alert sensitivity and choose a simulated or uploaded log.Tune how many failed logins trigger an alert. Changes apply to the next scan on this device.
Threat summary
2
potential threats found
· 2 to fix, 0 to review
· 0 ports in normal use
· 0 of 1 checks clear
How to read the colors
- Risk
- Something dangerous is open or turned off, or an attack sign was found. Fix these first.
- Review
- Probably needed, but worth a look: a risky port an app uses, or an unrecognized program other devices can reach.
- In use
- A recognized app or OS feature needs this port. Normal; close it only if you don't use that feature.
- Safe
- Closed, only reachable from this computer, or a protection that's turned on.
- Unknown
- Couldn't be checked on this system, usually because it needs admin rights.
IOC / CVE Analyzer
2
Risk
2 risk · 0 review · 0 in use
IOC / CVE Analyzer
RiskFlags brute-force SSH sources and open ports tied to known CVEs
2 indicator(s) found (demo log)
Log source: SAMPLE DATA (DEMO SCENARIO: Combined brute-force and password-spray scenario). No readable system SSH log was found, so a bundled example log is used.
- Risk Possible brute-force login activity Source 203.0.113.45. 4 failed logins from 203.0.113.45 targeted account root on local SSH service within 120 seconds. If this were a real log, block the source and use SSH keys.
- Risk Possible password-spraying activity Source 198.51.100.23. Failed logins from 198.51.100.23 targeted 6 accounts on local SSH service within 300 seconds. If this were a real log, block the source and use SSH keys.
- Safe Known-vulnerability ports None of the ports tied to well-known attacks (21, 23, 445, 3306, 3389, 5900) are open.
- Safe Log source DEMO DATA: DEMO SCENARIO: Combined brute-force and password-spray scenario