Endpoint/Overview
Devices6
320
sensor estate
Online1.4%
289
of 320
High exposure5
46
score ≥ 55
Open detections9
102
of detection stream
Critical CVE hosts2
130
unpatched critical
Sensor coverage0.8pp
67.5%
online + current agent

Detections vs blocked

Northline Systems · daily

DetectedBlocked
015314662MonTueWedThuFriSatSun
Mon Sensor auto-update waveWed Ransomware drill containedThu Critical CVE publishedSat Patch lag campaign kickoff

Fleet by OS

320 devices

121
Windows
71
macOS
64
Linux
31
iOS
33
Android

Highest exposure

score ≥ 55

DeviceOSExp
svc-build-runner-03Linux95
harper-mbp-77macOS95
diego-win-deskWindows94
finance-kiosk-02Windows94
jordan-xps-19Windows93
wren-air-65Android82
morgan-desk-88macOS77

Top exposure devices

unique · by score

Exposure
DeviceOwnerLagExposureTop signal
svc-build-runner-03Samir Patel91d95Critical CVE open on host
harper-mbp-77Harper Hayes31d95Critical CVE open on host
diego-win-deskDiego Alvarez55d94Critical CVE open on host
finance-kiosk-02Marcus Chen112d94Critical CVE open on host
jordan-xps-19Jordan Lee67d93Critical CVE open on host
wren-air-65Wren Beck124d82Critical CVE open on host
morgan-desk-88Morgan Hayes62d77Critical CVE open on host
val-mbp-46Val Owen45d76Critical CVE open on host

Posture health

sensor × exposure × lag

66
score
Sensor coverage68%
Online devices289
High exposure46
Avg patch lag35d
Lag ≥ 45d101

Detections by severity

stream mix

28
Critical
50
High
57
Medium
26
Low
19
Info

Agent activity, human approval

AI work · last 24h

EDR agent
Investigated
39
Actions proposed
5
Pending approval
4
Overrides
2
  • Credential dump attempt (LSASS)
    Investigation · diego-win-desk · verdict: malicious 92%
    07:44
  • Network isolate diego-win-desk
    Action · proposed by agent · LSASS investigation
    07:45
  • Full disk scan diego-win-desk
    Action · proposed by agent · LSASS investigation
    07:45
  • Outbound C2 beacon pattern
    Investigation · svc-build-runner-03 · verdict: suspicious 71%
    06:58
  • Mass file encryption behavior
    Investigation · jordan-xps-19 · verdict: malicious 96%
    Approved08:15
  • Network isolate jordan-xps-19
    Action · approved by Wei Chen · 08:18
    Approved08:18
  • Kill browser credential store access
    Action · denied by Elena Vargas
    override reason: FP, admin vault extension
    Overridden05:32
  • Mimikatz-like string in memory
    Investigation · wei-thinkpad-t14 · verdict: benign 88%
    Approved04:12
  • Quarantine unsigned persistence binary
    Action · overridden by Wei Chen
    override reason: Known dev tool, allowlisted
    Overridden03:47
  • Sensor tamper attempt
    Investigation · tom-helpdesk-01 · verdict: malicious 90%
    Approved02:20

Root-caused alerts

symptom → cause → fix

Do this next

scored from exposure · score × lag × critical CVEs

Exposure
#1238
Contain / remediate: svc-build-runner-03
Critical CVE open on host
exposure 95
#2139
Contain / remediate: harper-mbp-77
Critical CVE open on host
exposure 95
#3174
Contain / remediate: diego-win-desk
Critical CVE open on host
exposure 94
#4270
Contain / remediate: finance-kiosk-02
Critical CVE open on host
exposure 94
Operator console