{% extends "base.html" %} {% block title %}Overview & Killchain{% endblock %} {% block content %}
Decoy Sensors Active
4 / 4
100% Subnet Coverage • 55 Canary Tokens
24h Deception Hits
{{ threats|length }}
0 False Positives • 100% High Fidelity
Critical Ransomware Traps
3
High Entropy & Shadow Copy Tamper Intercepted
Quarantined Hosts
{{ containment|length }}
Mean Time to Contain: < 8.0s

🎯 Intercepted Ransomware Lateral Movement Killchain

Live Incident DG-CORR-INCIDENT-9942
1
Reconnaissance
T1046 SYN Sweep & MSRPC EPM Probe
10.240.12.84
2
Credential Abuse
T1078.002 NTLMv2 Compromised Service Acct
svc-backup
3
Lateral Movement
T1021.002 SMB ADMIN$ & PsExec Service Creation
Port 445/TCP
4
Canary Tripwire
T1486 Canary Encryption & Ransom Note
Entropy 7.98/8.0
5
Autonomous Quarantine
EDR Host Isolation & QRadar Reference Set
Containment < 10s

⚡ Live Deception Telemetry Stream (QRadar LEEF 2.0 Normalized)

View All Intercepts
{% for t in threats %} {% endfor %}
Time (UTC) Attacker Host / IP Target Decoy Target Port MITRE ATT&CK Severity Deception Signature Actions
{{ t.timestamp }} {{ t.src_host or t.src_ip }}
{{ t.src_ip }}
{{ t.dest_host or t.dest_ip }}
{{ t.node_id }}
{{ t.dest_port }}/{{ t.protocol|upper }} {{ t.mitre_technique_id }}
{{ t.mitre_technique }}
{% if t.severity_id >= 9 %} Critical ({{ t.severity_id }}) {% elif t.severity_id >= 7 %} High ({{ t.severity_id }}) {% else %} Medium ({{ t.severity_id }}) {% endif %}
{{ t.signature }}
{{ t.raw_payload[:60] if t.raw_payload else '' }}...
{% endblock %}