Incidentes
12 abiertos · 2 críticos · MTTR 41 min
Incidentes abiertos
12
▼ 2 críticos
Bloqueados hoy
18,402
● 96% escaneos y fuerza bruta
Tiempo medio de respuesta
41 min
▲ 12 min más rápido
Activos sin parche
61
▼ 9 CVE críticos
Volumen de ataques
00h06h12h18h24h
Por severidad
78%
Postura de seguridad
Incidentes abiertos
| ID | Incidente | Severidad | Activos | Responsable | Antigüedad | Estado |
|---|---|---|---|---|---|---|
| INC-4412 | Credential stuffing — portal de clientes | Crítico | 1 | KBK. Bonilla | 38 min | Conteniendo |
| INC-4409 | Ransomware precursor en FS-02 | Crítico | 3 | JFJ. Fernández | 1 h 12 m | Investigando |
| INC-4404 | Exfiltración sospechosa a IP en RU | Alto | 2 | KBK. Bonilla | 4 h | Investigando |
| INC-4398 | MFA deshabilitado en cuenta admin | Alto | 1 | MTM. Terrero | 6 h | Remediando |
| INC-4391 | Phishing dirigido a finanzas (9 buzones) | Medio | 9 | JFJ. Fernández | 11 h | Contenido |
| INC-4385 | Puerto RDP expuesto en VPS-07 | Medio | 1 | MTM. Terrero | 1 d | Corregido |
Detecciones en vivo
14:41:52 BLOCK 185.220.101.4 → portal.cliente 1,204 failed logins / 60 s
14:41:31 DETECT T1110.004 password spraying · rule cred-stuff-v3 · conf 0.94
14:40:08 ACTION auto-block source ASN 43350 · 24 h · playbook PB-11
14:38:44 ENRICH 185.220.101.4 → TOR exit node · abuse score 91/100
14:22:10 DETECT vssadmin delete shadows on FS-02 · host isolated
14:22:10 ACTION FS-02 quarantined from network · 3 sessions killed
13:58:02 DETECT 2.1 GB outbound to 91.219.x.x over 40 min · user rgarcia
13:12:44 PATCH CVE-2026-1188 applied to 14 of 23 hosts
Exposición
Activos expuestos a internet38
CVE críticos abiertos9
Cuentas admin sin MFA2
Respaldos verificadosAyer 03:10
Última prueba de restauración2026-08-03
Cobertura EDR96% (212 / 221)