Terminal
Evidence Console
Try:
help, alerts, auth --failures, ip 203.0.113.50, user j.smithBlue Team Room
You are the analyst on shift. Review the alert evidence, investigate the login pattern, identify the suspicious IP, and choose the best immediate action.
Terminal
help, alerts, auth --failures, ip 203.0.113.50, user j.smithObjectives