Threat Detection & Incident Response Intelligence

FinShield Corp SOC | 3,200 endpoints | Last 30 days

Last updated
Dec 18, 2024 14:32 UTC
MTTD
42m
54% vs last month
MTTC
3.8h
39% vs 6.2h
Alert Fidelity
31%
+13pp from 18%
TTP Coverage
68%
+5pp vs Q3
EDR Coverage
94%
+2pp this week
Exploit Attempts
142/d
18% vs last week

MTTD & MTTC Trend — Last 30 Days

Detection Rule Signal-to-Noise Leaderboard

Rule Name Alerts True + SNR Action
Pass-the-Hash Attempt127413.1Keep
Lateral Auth Anomaly94283.4Keep
Kerberoasting Detection63173.7Keep
Suspicious PowerShell1,8428721.2Tune
Office Macro Exec2,1043461.9Suppress
DNS Tunneling4121921.7Tune
Failed RDP Brute Force3,28712273.9Suppress
Mimikatz Signature18141.3Keep

MITRE ATT&CK TTP Coverage

Lateral Movement Indicator Frequency

Threat Actor Attribution

TA505 (Pass-the-Hash) 41 events
APT29 (Kerberoasting) 17 events
Unknown (DNS Tunneling) 19 events
FIN7 (Living-off-the-Land) 8 events

Open Critical Vulnerabilities by Exploitability

CVE ID Asset CVSS Exploit Pub Age (days) Status
CVE-2023-46604prod-app-0310.0Public127Patching
CVE-2023-44487lb-frontend-019.8Public94Patching
CVE-2024-21762vpn-gateway-029.6Public63Testing
CVE-2023-36884ws-finance-129.8PoC51Testing
CVE-2024-3400fw-perimeter-0110.0Public38Patching
CVE-2023-27350pbx-voip-core9.8Public29Scheduled

Alert Fidelity Trend (12wk)

Mean Time to Escalate

Incident Severity Distribution

Endpoint Telemetry Coverage by Environment

Top Detection Gaps

T1070 - Indicator Removal
0%
T1048 - Exfiltration Over Alternative
18%
T1547 - Boot/Logon Autostart
22%
T1078 - Valid Accounts
41%
T1055 - Process Injection
87%

SOC Capacity Utilization

78%
Alert triage workload

SOAR Playbook Coverage

Phishing Response 100%
Malware Containment 94%
Lateral Movement 87%
Data Exfiltration 63%
Insider Threat 41%

Analyst Performance

Avg. Triage Time
8.2min
Escalation Accuracy
91%
Cases Closed/Analyst
34/day