Correlated Incidents
Legion's high-priority, correlated incidents built from multiple alerts and entities across the unified ontology.
| ID | Title | Severity | Status | Entities | Events | Detected |
|---|---|---|---|---|---|---|
| 00INC-3 | Cloud Misconfiguration: arn:aws:s3:::customer-exports Cloud Guardian Detective | MEDIUM | Open | 3 | 3 | about 1 hour ago |
| 0INC-11 | Suspicious Cloud Activity Pattern SIEM Correlator | HIGH | Open | 4 | 4 | about 1 hour ago |
| 00INC-8 | Compromised Device: WIN-ENG-02 Endpoint Hunter, SIEM Correlator | HIGH | Open | 4 | 3 | about 1 hour ago |
| 0INC-10 | Credential Theft Followed by Lateral Movement SIEM Correlator | HIGH | Open | 5 | 3 | about 1 hour ago |
| 00INC-2 | Suspicious Identity Activity: sarah.patel@legion-demo.com IAM Patrol Detective, Endpoint Hunter, SIEM Correlator | CRITICAL | Open | 3 | 2 | about 2 hours ago |
| 00INC-5 | Compromised Device: WIN-ACCT-01 Endpoint Hunter, SIEM Correlator | HIGH | Open | 4 | 3 | about 2 hours ago |
| 00INC-7 | Compromised Device: WIN-ACCT-01 Endpoint Hunter, SIEM Correlator | HIGH | Open | 4 | 3 | about 2 hours ago |
| 00INC-9 | Multi-Domain Attack Chain Detected SIEM Correlator | CRITICAL | Open | 4 | 3 | about 2 hours ago |
| 0INC-12 | Impossible Travel with Data Exfiltration SIEM Correlator | CRITICAL | Open | 4 | 3 | about 2 hours ago |
| 0INC-14 | Repeated MFA Failures Followed by Access SIEM Correlator | HIGH | Open | 3 | 2 | about 3 hours ago |
| 00INC-1 | Suspicious Identity Activity: tom.nguyen@legion-demo.com IAM Patrol Detective, Endpoint Hunter, SIEM Correlator | CRITICAL | Open | 3 | 2 | about 4 hours ago |
| 00INC-6 | Compromised Device: MAC-FIN-01 Endpoint Hunter, SIEM Correlator | HIGH | Open | 4 | 3 | about 4 hours ago |
| 0INC-13 | Ransomware Behavior Detected SIEM Correlator | CRITICAL | Open | 3 | 2 | about 4 hours ago |
| 00INC-4 | Cloud Misconfiguration: arn:aws:iam::123456789012:role/AdminRole Cloud Guardian Detective | MEDIUM | Open | 3 | 3 | 1 day ago |