Module 02

Threat Monitor

Track detections across identity, email, web, network and application surfaces in a prioritised, filterable feed.

Simulated Demo Data — All threat intelligence shown below is simulated for demonstration purposes. No real-time threat feeds are connected.

Active threats

12

3 critical, 9 investigating

Mitigated today

47

Across all surfaces

Mean time to detect

4.2m

Rolling 7-day average

Sources monitored

18

Feeds active

Global threat map

Geographic distribution of detected threats

North America

342 threats

Europe

289 threats

Asia Pacific

456 threats

South America

124 threats

Africa

87 threats

Middle East

156 threats

North America342
Europe289
Asia Pacific456
South America124
Africa87
Middle East156

Severity distribution

Threats by severity level

Critical
24
High
67
Medium
134
Low
89
Info
42

Threat activity timeline

24-hour view by threat type

Phishing
Malware
Ransomware

Threat categories

Breakdown by attack type

+12%

Phishing

189

detected

+8%

Malware

156

detected

+22%

Ransomware

34

detected

-5%

DDoS

78

detected

+15%

Credential Theft

245

detected

+3%

Data Breach

67

detected

Threat feed

Prioritised by severity and recency

  • Credential stuffing campaign targeting SSO portals

    THR-9041 · Breach intelligence · 8m ago

    IdentityActive

    14,200 unique credentials in rotation

  • Look-alike domain mimicking payment provider

    THR-9038 · URL reputation · 22m ago

    WebInvestigating

    secure-paypa1-verify.co

  • Spear-phishing wave with PDF attachment

    THR-9034 · Mail gateway · 1h ago

    EmailMitigated

    Invoice_Q3_2026.pdf.lnk

  • Anomalous API call volume from third-party integration

    THR-9029 · API monitor · 2h ago

    ApplicationInvestigating

    3.4x baseline request rate

  • Outdated TLS 1.0 connection attempt blocked

    THR-9023 · Edge firewall · 3h ago

    NetworkMitigated

    Legacy client — connection refused

  • Suspicious browser extension exfiltrating cookies

    THR-9018 · Endpoint agent · 4h ago

    EndpointActive

    chrome-extension://kdfj3…

  • DNS tunneling pattern detected on workstation

    THR-9012 · DNS monitor · 5h ago

    NetworkInvestigating

    Unusual TXT query volume

  • New CVE published for widely-used auth library

    THR-9007 · Advisory feed · 6h ago

    VulnerabilityInvestigating

    CVE-2026-48210 — CVSS 7.5

Threats by surface

Last 24 hours

  • Identity & auth
    342+12%
  • Email & messaging
    189+8%
  • Web & browsing
    156-3%
  • Network & endpoints
    98-6%
  • Application layer
    74+5%
  • Vulnerability intel
    61+2%