■ NetSecDen
SIEM DashboardTotal
—
Critical
—
High
—
Medium
—
Clients
—
Events Over Time (last 24h)
Loading…
Threat Distribution
—
Total
Critical Devices
Top Alerting Entities
Threat Map firewall & network sources, last 24h
Loading…
Recent Activity new device registrations
Loading…
THREAT LEVEL: —
Total
—
Critical
—
High
—
Medium
—
Clients
—
| Time | Company | Device | Severity | Category | Title | AI |
|---|
Active Infections
—
Recent (30d)
—
Isolated
—
Stale Endpoints
—
Sites
—
No Coverage
—
Total Findings
—
Last poll: —
Endpoints scanned: —
Sites: —
New findings: —
Site Summary
| Site | Active Infections | Recent Infections | Isolated | Stale | Other | Total |
|---|
Findings
| Time | Endpoint | Site | Severity | Type | Detail |
|---|
Offline Servers
—
Offline Agents
—
Disk Warnings
—
Active Alerts
—
Customers
—
Total Findings
—
Last poll: —
Agents scanned: —
Alerts scanned: —
New findings: —
Customer Summary
| Customer | Offline Servers | Offline Agents | Disk Warnings | Active Alerts | Total |
|---|
Findings
| Time | Device | Customer | Severity | Type | Detail |
|---|
Critical
—
High
—
IPS Events
—
VPN Events
—
Auth Failures
—
Network (UniFi)
—
Total
—
SonicWall Listener: —
Received: —
Inserted: —
UniFi: —
| Time | Severity | Category | Event | Detail |
|---|
📡 Traffic Usage
Total Transferred
—
Outbound (Sent)
—
Inbound (Rcvd)
—
Flows Logged
—
Top Talkers (Source IPs)
| IP | Company | Sent | Rcvd | Flows |
|---|
Top Destinations
| IP | Sent | Rcvd | Flows |
|---|
Protocol Breakdown
Hourly Bandwidth
Scroll/pinch to zoom, drag to pan, or use the +/−/reset controls in the bottom-left corner of the diagram.
Nodes (sites / firewalls / hosts / VMs)
| Name | Type | Site | IP | Role |
|---|
Applications
| App | Node | Port | Public host |
|---|
Connections
| From | To | Type | Label |
|---|
Critical
—
Sign-in / Identity
—
Mailbox / BEC
—
License / Users
—
Defender Alerts
—
Total Findings
—
Status: —
Last poll: —
Users scanned: —
New findings: —
Pruned: —
| Time | Severity | Category | User / Object | Title | Detail |
|---|
Total Devices
—
Online
—
Offline
—
Servers
—
Workstations
—
Companies
—
| Status | Device | Company | Type | OS | CPU | RAM | Disks | IP Address | Last Seen |
|---|
🖥 Server Hardware Health (iDRAC)
Servers Monitored
—
Critical
—
High
—
RAID / Disk
—
Non-Enterprise License
—
iDRAC Poller: —
| Time | Severity | Server | Category | Event | Detail |
|---|
Select a company and click Generate Report
Total Breaches
—
Critical
—
High
—
Domains
—
Companies
—
HIBP last poll: —
Domains checked: —
New findings: —
Breach Intelligence (HaveIBeenPwned)
| Detected | Severity | Company | Domain | Finding | Detail |
|---|
No breach intelligence findings yet. Configure hibp_config.json and run a poll to start.
Exposed Services
—
Critical
—
High
—
CVEs
—
IPs Monitored
—
Companies
—
Shodan last poll: —
IPs scanned: —
New findings: —
Resolved: —
Attack Surface (Shodan)
| Detected | Severity | Company | IP | Type | Finding | Detail |
|---|
No attack surface findings yet. Configure shodan_config.json and run a poll to start.
YARA: —
Volatility: —
Log2timeline: —
Total Jobs
—
Pending / Running
—
YARA Hits
—
Memory Findings
—
Timeline Events
—
Submit New Job
Job Type
Company
Hostname
Files (artifacts, dump, etc.)
Job Queue
| Created | Type | Status | Company | Hostname | Findings | Summary / Error | Duration |
|---|
No forensic jobs yet. Run sift_setup.ps1 on the server, then submit a job above.
Tracked IPs
—
Total Sessions
—
Total Volume
—
| Rank | IP Address | Sent | Received | Total | Sessions |
|---|
Configure which severity levels auto-create a ticket in the helpdesk for each company.
Changes save instantly.
| Company | Tickets On | ■ Critical | ■ High | ■ Medium | ■ Low | Notify Email |
|---|
AI Computer Agent
Powered by Claude Opus. Diagnoses and fixes Windows issues — system files, printers, memory — and correlates with SIEM findings.
Start New Session
Registered Endpoints
Loading...
Sessions
No sessions yet.
Add Company
| Company |
|---|
Create Company Login
Existing Users
| Name | Company | Role | Created |
|---|
SMS Alert Recipients
Texts critical & high severity findings to these numbers via carrier email gateway.
| Name | Number | Carrier | Enabled |
|---|
No recipients configured yet.
Recent SMS Alerts
| Time | Recipient | Finding |
|---|
No alerts sent yet.
| Status | Hostname | Client ID | IP Address | Registered | Last Seen |
|---|