sentinel.shannon.id/dashboard
Maju Industri Dasbor

Selamat datang kembali, Budi!

2 temuan kritis memerlukan perhatian dan 1 temuan menunggu tinjauan analis. Ke Triase →

Jejak audit → Pengaturan domain
Temuan Kritis
0
+1 dari pindaian terakhir
Temuan Tinggi
0
Tidak berubah dari pindaian terakhir
Sedang
0
Semua bersih
9/10 temuan terverifikasi 1 abstain — menunggu tinjauan analis Tinjau di Triase →
Tren Peringatan
25 Mei – 5 Jul
Filter
May 25
May 31
Jun 6
Jun 12
Jun 18
Jun 24
34Jun 30
Rincian Sumber Temuan 12 temuan
Keamanan Email3
Jaringan & Perimeter3
Manajemen Log3
Identitas & Akses2
Web & Subdomain1
Status Temuan 6 domain
Terbuka4
Pemantauan3
Selesai5
8/9 temuan ≥2 sitasi independen

Incident Response Playbooks

AI-guided containment steps for active incidents — block, isolate, escalate — each requiring your approval before execution.

0
Alerts triaged today
0
Avg. AI confidence
0
Auto-triage rate
0
HITL approvals pending

Brute Force Response

ssh.domain.com · 14:07 WIB · 847 failed attempts

Verified 5/5 Active
1. Alert ingested and classified
T1110.001 Brute Force — AI confidence 94%. Source IPs: 45.152.67.23, 185.220.101.9, 91.240.118.172.
2. Log enrichment & correlation
No successful logins. All 3 source IPs flagged in AbuseIPDB — 2 independent citations, meets the ≥2 rule.
3. Block source IPs at firewall
Add deny rules for 45.152.67.23/32, 185.220.101.9/32, 91.240.118.172/32.
Human Approval Required
This action modifies firewall rules. Review and approve before execution.
ApproveReject
Approved — executing… · Budi S. · 14:12
4. Disable SSH password authentication
Set PasswordAuthentication no in /etc/ssh/sshd_config and reload sshd.
Human Approval Required
This changes host authentication config. Review and approve before execution.
ApproveReject
Approved — executing… · Budi S. · 14:13
5. Create incident ticket & notify team
Open DFIR-IRIS case with the evidence bundle. Notify the on-call analyst.
Human Approval Required
This opens an external case and pages a person. Review and approve before execution.
ApproveReject

Audit Trail

14:07Alert ingestedPolicy · auto
14:09Enrichment completePolicy · auto

AI Governance

Shannon SOC Agent Active
AI Agent Awaiting Your Decision
These tool calls are blocked until a human approves or rejects them.
3
Pending Actions Requires human decision before execution
Medium risk3 min ago
read_employee_records(department="finance", limit=50)
Correlating identity anomaly with employee access patterns — HR data access requires approval.
ApproveReject
High risk7 min ago
update_dlp_policy(rule_id="ext-upload-block", add_exception="trusted-vendor.co.id", duration="7d")
Temporary DLP exception for vendor data transfer — policy modification requires human approval + audit.
ApproveReject
Rejected — action blocked · Budi S. · 14:24
Medium risk15 min ago
send_executive_brief(recipients=["ceo@…","ciso@…"], subject="Incident Summary Q2")
AI-generated incident summary for C-suite. First-time external send requires approval.
ApproveReject
Policy Rules Add Rule

Requires approval

Access HR / employee recordsHuman approval
Modify security policy+ audit
Send external communicationHuman approval
Export data externally+ audit
Update knowledge baseHuman approval

Auto-approved

Query external threat intelAuto
Read log dataAuto
Generate compliance reportAuto
Audit Log Export CSV
TIMETOOL CALLDECISIONBY
14:21generate_compliance_report(framework="ISO27001")AUTOPolicy
14:17read_employee_records(dept="finance", limit=50)APPROVEDBudi S.
14:12read_logs(source="firewall", days=3)AUTOPolicy
47 agent actions today — 100% logged and attributable

2 steps approved

Audit trail recorded · Budi S. · 14:13 WIB
01Dashboard 02Triage 03AI Governance
AGENTIC SOC · BAHASA & ENGLISH
The agent acts.
Every action is logged, scoped, and yours to approve.
Human-in-the-loop by policy, not by promise — 47 agent actions today, 100% attributable.

Motion is reduced in your system settings, so the reel doesn't start on its own.

0:00 / 0:45