← Acme Corp
Agent logs — WS-ACME-01
Agent heartbeat, action results, inventory status and telemetry received by the console.
-
process_start high
{ "process_name": "powershell.exe", "cmdline": "powershell -enc JABj...", "user": "CORP\\jsmith" } -
network_connect critical
{ "remote_ip": "185.220.101.45", "remote_port": 4444, "protocol": "tcp" } -
process_start medium
{ "process_name": "cmd.exe", "cmdline": "cmd /c whoami", "user": "CORP\\admin" } -
network_connect low
{ "remote_ip": "8.8.8.8", "remote_port": 53, "protocol": "udp" } -
agent_status low
{ "status": "ok", "message": "heartbeat ok", "version": "1.2.0" } -
network_threat high
{ "remote_ip": "45.33.32.156", "reason": "known_c2", "action": "blocked" } -
process_start critical
{ "process_name": "mimikatz.exe", "cmdline": "mimikatz privilege::debug", "user": "SYSTEM" } -
inventory_scan low
{ "packages_scanned": 847, "duration_ms": 12400 } -
action_result low
{ "action_type": "full_scan", "status": "completed", "findings": 0 } -
network_delta medium
{ "new_connections": 3, "closed_connections": 12 }