AZ
Back to sessions

unx_08lnjpc

26
User: o••••••••@example.dev🇵🇹PT209.244.•••.•••AS12389 Rostelecom
Open in graph
Final decision
Approved· 26 / 100
Driven primarily by:
  • Known malware signature92
  • Process injection84

Fired signals

Each card explains what the signal means and why it fired.

Malware
Known malware signature
92
A file hash on the endpoint matches an active malware family signature.
Process injection
84
EDR telemetry shows injected code running in the browser context.

Risk breakdown

Contribution to the final score by category.

  • Device0
  • Behavior0
  • Network0
  • Identity0
  • Malware176

Event timeline

Everything that happened during this session.

  1. Session start6:54:13 PM
    RemoteAccess · AS12389 Rostelecom
  2. iPhone · iPhone 146:54:18 PM
    fp_000062j
  3. Known malware signature6:54:43 PM
    severity 92
  4. Process injection6:54:52 PM
    severity 84
  5. Opened /transfer6:54:56 PM
  6. Approved6:55:25 PM