WS-3 · D-13/D-14

Security Operations Centre

SIEM event stream, IDS / IPS posture and 24/7 monitoring across edge, app and cloud.

-3 vs yesterday
7
Open alerts
SLA < 10m
4.2m
Mean time to detect
SLA < 30m
18m
Mean time to respond
100% coverage
1,284
Endpoints monitored
Live SIEM event feed
EventTimeSeveritySourceDetectionHost / IPStatus
E-941214:32:08criticalIDS / SuricataET POLICY Outbound SSH from container
edge-fn-eu-west-3
10.0.4.21
open
E-941114:28:41highWAF / CloudflareSQL Injection attempt blocked
api.festicket.io
203.0.113.42
blocked
E-941014:21:09mediumAuth / Supabase5 failed logins · same IP
auth.festicket.io
198.51.100.7
investigating
E-940914:02:55lowEDR / CrowdStrikeUnsigned binary executed
dev-laptop-marta
acknowledged
E-940813:51:30highCloud / AWS GuardDutyS3 bucket made public
festicket-media
remediated
E-940713:44:12mediumIDS / SuricataPort scan detected
ingress-gw-1
192.0.2.88
blocked
E-940613:30:00lowDLP / NightfallPII pattern in Slack message
slack-workspace
acknowledged
IDS / IPS sensors
Suricata IDS
Network IDS · Edge + VPC peering
142
healthy
Cloudflare WAF
Application IPS · api.festicket.io / *.festicket.io
88
healthy
CrowdStrike Falcon
Endpoint EDR · 1,284 endpoints
9
healthy
AWS GuardDuty
Cloud workload IDS · 3 accounts · 12 regions
21
degraded
Encryption posture
  • Data at rest
    PostgreSQL · AES-256 · KMS-managed
  • Data in transit
    TLS 1.3 · HSTS · 100% endpoints
  • Secrets manager
    AWS Secrets Manager · 90-day rotation
  • DLP scanning
    PII / PAN patterns · Slack + Email
  • Breach response plan
    Runbook v2.4 · last tabletop 12 Aug