Detection & Response
Threat Map
Live map of attack origins and targets.
Available as a standalone module · Add to my package12Open incidents
41,208Events / sec
27Auto-contained
- Real-time attack flowsActive
- GeoIP enrichmentActive
- Top source countries and targetsActive
- Click through to the eventsActive
What it does
A live geographic view of where attacks come from and which of your assets they target, enriched with GeoIP and threat intel.
Real-time attack flows
GeoIP enrichment
Top source countries and targets
Click through to the events
How it worksin three steps.
Collect
Events from agents, syslog and connectors are normalised into one schema.
Detect
SIGMA, YARA and IOC matches run in real time and are correlated into incidents.
Respond
Contain the threat from the console, with approval for high-impact actions.
Works best withthese modules.
See all 30 modules
Endpoint Security
Agents
Signed lightweight agents for Windows, Linux and macOS.
Learn more Threat IntelligenceThreat Intelligence Feeds
IOC feeds matched against every event.
Learn more Automation & AISOC Automation
Visual flows from detection to response.
Learn moreAlso in Detection & Response
Ready to see it on your own data?
A 30-minute walkthrough with an engineer, tailored to your environment.