| COG-2026-001 |
2026-07-30 17:41:09 |
192.168.43.112 |
Anomalous Data Exfiltration |
Behavior matches known patterns of APT29 lateral movement. Unusual high-frequency data transfer observed outside business hours. |
98.4% |
✔️ Endpoint Isolated via SOAR |
High |
| COG-2026-002 |
2026-07-30 17:27:09 |
10.0.12.45 |
Credential Stuffing / Brute Force |
NLP Analysis parsed suspicious SSH access failure sequences accompanied by rapid unauthorized profile mutations. |
89.1% |
✔️ IP Temporarily Blocked |
High |
| COG-2026-003 |
2026-07-30 16:45:09 |
172.16.5.99 |
Suspicious PowerShell Execution |
Unsupervised cluster baseline deviation detected localized code execution accessing protected registry hives. |
76.5% |
✔️ Flagged for Analyst Review |
Medium |
| COG-2026-004 |
2026-07-30 14:45:09 |
192.168.1.204 |
Internal Network Scanning |
Multi-vector heuristic probing detected. Sub-threshold port connectivity sweeps identified natively. |
62% |
✔️ Suppressed / Monitored |
Low |