Synthesize the investigative process of network forensic specialists with chainable decision trees.
IRES starts with PacketSled’s core foundation of high fidelity network data.
Any observed alert, stastic, analytic or single piece of metadata can launch an automatic investigation which will follow a logical decision tree.
IRES then creates a simple to read report which identifies the assets involved and the nature of the attack.
The result:
Automatic incident verification
1
|
80.0.87.35 attempted 4,300 logins against 10.10.1.14
|
2
|
80.0.87.35 successfully acquired access to 10.10.1.14
|
3
|
10.10.1.14 conducted an address scan
|
4
|
10.10.1.14 triggered a Joomla RCE exploit on 10.10.1.14
|
5
|
Outbound transfer of 1.2Gb from 10.10.1.14 to 113.22.18.1
|
© 2016 PacketSled, Inc.