Correlates authentication activity, endpoint execution, network sessions, cloud events, vulnerabilities, behavioral context, and deception evidence to reconstruct initial access.
Determine scope
Supports enterprise-wide historical search across identities, endpoints, network activity, cloud resources, and deceptive assets to identify affected entities and related behavior.
Determine impact
Provides process, file, session, protocol, data-movement, and behavioral evidence to assess what the attacker accessed, changed, transferred, encrypted, or disrupted.
Preserve evidence
Supports endpoint artifact collection, memory analysis, historical event retention, session metadata, PCAP export, extracted files, and investigation records.
Support containment
Helps teams identify the hosts, identities, sessions, workloads, credentials, and connections that require containment.
Improve future detection
Enables retrospective hunting with new indicators, YARA rules, OpenIOC definitions, behavioral findings, and threat intelligence.