Attack story · Pillar 06

The whole story,
before the alert fired.

For every alert, KosmicSignal reconstructs the timeline leading up to the trigger — what the entities did, how each step enriches, and a deterministic score you can reproduce and defend. Analysts open a scene, not a single frozen row.

−60 → trigger windowDeterministic scoringProvenance on every fact
Request a demo All pillars
ATTACK STORY · user jsmith@corp −60m−40mNew-IP sign-in185.x geo: NL−12mGlobal Admin roleprivilege esc.0mALERT FIRESimpossible travel+3mKey Vault readsecrets accessed+15m DETERMINISTIC SCORE 87 reproducible · provenance on every signal
Every action around the trigger, scored deterministically.
The problem

An alert is one row: a rule name and a timestamp. The question that matters — what was actually happening around that moment — takes an analyst five consoles and twenty minutes to answer by hand. KosmicSignal answers it automatically.

−60/+15
minute window
Deterministic
scoring
100%
provenance
How it works

What you get.

Timeline to the trigger

A window around the alert (default −60/+15 minutes) shows every relevant action — sign-ins, role changes, process executions, resource access — in sequence.

Entity enrichment

Each actor, host, IP and indicator is enriched with identity, geo, threat intel and UEBA context, assembled at view time.

Deterministic scoring

The risk score is computed from explicit signals — no black box. The same evidence always yields the same score, so it holds up in review.

Provenance on everything

Every fact names its source and query time, so an analyst — or an auditor — can trace exactly where a conclusion came from.

In the product

See it live.

kosmicsignal.com/app
The alert attack story
The alert attack story
kosmicsignal.com/app
Evidence & enrichment
Evidence & enrichment
Works with
See KosmicSignal in action

A walkthrough of
the live product.

Request a demo →
No obligation. A look at the actual platform, on your data.