# Solutions

# We triage what other platforms can't

Other AI SOC platforms have coverage ceilings. They rely on pre-defined logic and follow fixed triage questions.
Radiant uses a structured 5-step investigation process designed to handle any alert, from the common to the complex.

[Book a Demo](https://radiantsecurity.ai/book-a-demo/)

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Solution-page-hero-large2.png)

Other AI SOC platforms have coverage ceilings. They rely on pre-defined logic and follow fixed triage questions.
Radiant uses a structured 5-step investigation process designed to handle any alert, from the common to the complex.

[Book a Demo](https://radiantsecurity.ai/book-a-demo/)

# Triage any alert with Radiant’s
5-Step Methodology

# The triage process: What we do

Radiant follows the same investigative flow a human analyst would: understand → enrich → plan → execute → conclude.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Classification.svg)

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/1Classification.svg)

### Classification

AI interprets the characteristics of a raw alert to determine it’s type of threat, and understand whether it has encountered it before. This determines if a plan will be re-used or generated from scratch in step 3.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Enrich.svg)

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/1Enrich.svg)

### Enrich

AI automatically pulls in context from across your environment: threat intelligence, identity data, asset information, and more, so your team has everything they need to make a decision without manually stitching data together.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/12Classification.svg)

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/1Plan.svg)

### Plan

AI plans the structured set of steps that determines exactly how the alert will be investigated. Plans are built dynamically based on: Radiant’s expert knowledge, your unique environment, and context memory.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Execute.svg)

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/1Execute.svg)

### Execute

AI runs automatically to answer each investigative question, pulling information from your connected security tools, SIEMs, and external data sources without any manual effort from your analysts.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Conclude.svg)

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/1Conclude.svg)

### Conclude

AI provides a transparent verdict by weighing malicious indicators against benign ones. Once analysts review and validate the reasoning of escalated alerts, they can group related alerts into a case, where they can view the full threat picture and take action from a single place.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Line-8.svg)

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/1Classification.svg)

### Classification

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Classification.svg)

AI interprets the characteristics of a raw alert to determine it’s type of threat, and understand whether it has encountered it before. This determines if a plan will be re-used or generated from scratch in step 3.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/1Classification.svg)

### Enrich

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Enrich.svg)

AI automatically pulls in context from across your environment: threat intelligence, identity data, asset information, and more, so your team has everything they need to make a decision without manually stitching data together.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/1Classification.svg)

### Plan

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/12Classification.svg)

AI plans the structured set of steps that determines exactly how the alert will be investigated. Plans are built dynamically based on: Radiant’s expert knowledge, your unique environment, and context memory.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/1Classification.svg)

### Execute

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Execute.svg)

AI runs automatically to answer each investigative question, pulling information from your connected security tools, SIEMs, and external data sources without any manual effort from your analysts.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/1Classification.svg)

### Conclude

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Conclude.svg)

AI provides a transparent verdict by weighing malicious indicators against benign ones. Once analysts review and validate the reasoning of escalated alerts, they can group related alerts into a case, where they can view the full threat picture and take action from a single place.

# The output for analysts: What you see

See how we deliver the details that matter the most once triage is completed.

Click through to see examples of each alert type.

Dark Web Endpoint DLP Identity WAF Network OT/IoT Cloud Insider Threat SIEM Supply Chain Email

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/dwicon.svg)

##### ![](https://radiantsecurity.ai/wp-content/uploads/2026/03/malicious-Stroke.svg) Recommended Malicious

#### Active phishing site impersonating customer portal

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon-source.svg) Escalate to Case

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon987.svg)

##### Classification

#### Site Impersonation

A suspicious domain impersonating Blast Labs' customer portal was identified and confirmed active. It is presenting a near-identical replica of the legitimate login page and posing a credible phishing risk to both employees and customers.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon987.svg)

##### Classification

#### Site Impersonation

A suspicious domain impersonating Blast Labs' customer portal was identified and confirmed active. It is presenting a near-identical replica of the legitimate login page and posing a credible phishing risk to both employees and customers.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon765.svg)

##### Planning and Execution

#### AI triage findings

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/qlogo-source.svg) ![](https://radiantsecurity.ai/wp-content/uploads/2026/04/wlogo-source.svg) ![](https://radiantsecurity.ai/wp-content/uploads/2026/04/elogo-source.svg)

**Is the flagged domain still live and serving content?**

The site is confirmed live, rendering a full replica of Blast Labs customer login page.

**Does the phishing site closely resemble the legitimate Blast Labs portal?**

Logo, color scheme, and login form are near-identical to portal.blastlabs.com .

**Was the domain recently registered with signs of malicious intent?**

The domain was registered 6 days ago with privacy protection enabled — consistent with phishing infrastructure.

**Is the hosting IP linked to any known phishing campaigns?**

IP is tied to other phishing campaigns targeting SaaS companies in the past 60 days.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon54654.svg)

##### Enrichment

#### Involved artifacts

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector45Stroke.svg) blastlabs-secure-login.com

resolving to attacker-controlled infrastructure

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector45Stroke.svg) 91.238.181.44 (Sofia, Bulgaria)

serving a convincing replica of

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector45Stroke.svg) https://blastlabs-login.com/login

visually mimicking legitimate protected asset

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector45Stroke.svg) https://portal.blastlabs.com/login

presenting an untrusted TLS certificate

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/12icon.svg) blastlabs-secure-login.com

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon65765.svg)

##### Response

#### Take action

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/qicon.svg)

##### Submit domain takedown request

#### ZeroFox

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/wicon.svg)

##### Block domain

#### Palo Alto Networks

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/eicon.svg)

##### Notify customer success and employees

#### Email

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/epoiicon.svg)

##### ![](https://radiantsecurity.ai/wp-content/uploads/2026/03/malicious-Stroke.svg) Recommended Malicious

#### Disguised update file triggered ransomware on corporate endpoint

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon-source.svg) Escalate to Case

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon987.svg)

##### Classification

#### Ransomware Disguised as Update

Employee executed a file disguised as a routine software update on their corporate endpoint — triggering a ransomware deployment that attempted encrypting local and network-accessible files within seconds.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon987.svg)

##### Classification

#### Ransomware Disguised as Update

Employee executed a file disguised as a routine software update on their corporate endpoint — triggering a ransomware deployment that attempted encrypting local and network-accessible files within seconds.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon765.svg)

##### Planning and Execution

#### AI triage findings

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/7868767logo-source.svg) ![](https://radiantsecurity.ai/wp-content/uploads/2026/04/9Frame1707483947.svg)

**Did the process spawn any child processes or attempt lateral movement?**

Update.exe spawned svchost.exe and began enumerating network shares within seconds of execution.

**Is the contacted domain associated with any known malicious activity?**

The domain is flagged as an active ransomware command-and-control server with recent malicious activity.

**Has this user executed similar suspicious files recently?**

No prior suspicious executions found — this is the user's first encounter with this file.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon54654.svg)

##### Enrichment

#### Involved artifacts

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector45Stroke.svg) blastlabs-secure-login.com

resolving to attacker-controlled infrastructure

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector45Stroke.svg) 91.238.181.44 (Sofia, Bulgaria)

serving a convincing replica of

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector45Stroke.svg) https://blastlabs-login.com/login

visually mimicking legitimate protected asset

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector45Stroke.svg) https://portal.blastlabs.com/login

presenting an untrusted TLS certificate

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/12icon.svg) blastlabs-secure-login.com

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon65765.svg)

##### Response

#### Take action

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/qicon.svg)

##### Submit domain takedown request

#### ZeroFox

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/wicon.svg)

##### Block domain

#### Palo Alto Networks

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/eicon.svg)

##### Notify customer success and employees

#### Email

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/lkjicon.svg)

##### ![](https://radiantsecurity.ai/wp-content/uploads/2026/03/malicious-Stroke.svg) Recommended Malicious

#### Sensitive file download detected from Salesforce

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon-source.svg) Escalate to Case

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon987.svg)

##### Classification

#### High-priority insider data exfiltration

A departing employee downloaded a sensitive sales leads file from Salesforce without authorization and immediately uploaded it to a personal Gmail account.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon987.svg)

##### Classification

#### High-priority insider data exfiltration

A departing employee downloaded a sensitive sales leads file from Salesforce without authorization and immediately uploaded it to a personal Gmail account.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon765.svg)

##### Planning and Execution

#### AI triage findings

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/logo-source.svg) ![](https://radiantsecurity.ai/wp-content/uploads/2026/04/2logo-source.svg) ![](https://radiantsecurity.ai/wp-content/uploads/2026/04/3logo-source.svg)

**Does this user have the permissions to access sensitive CRM sales data?**

The user holds no IAM roles or entitlements authorizing access to sensitive Salesforce sales records.

**Was the downloaded file transferred to any external destination?**

A follow-on DLP alert confirmed the file was uploaded to Gmail shortly after the Salesforce download.

**Is the user currently flagged offboarding or a departure risk or?**

The user is actively marked as departing the organization in Workday, placing this event in a high-risk insider threat context.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon54654.svg)

##### Enrichment

#### Involved artifacts

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/876iicon.svg) amelia@blastsecurity.com

using managed device

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector876Stroke.svg) agreen-MacBook Air

from Columbus, Ohio

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector45Stroke.svg) 3.146.43.227

logged into SaaS app

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/7786jhkjhicon.svg) Salesforce

and downloaded file

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/87879icon.svg) 026 enterprise salesleads.xlsx

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon65765.svg)

##### Response

#### Take action

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/kejh338icon.svg)

##### Suspend Amelia Green’s account

#### Google IAM

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/wicon.svg)

##### Revoke active sessions and auth tokens

#### Google IAM

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/eicon.svg)

##### Notify stakeholders to recover lost data

#### Email

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon.svg)

##### ![](https://radiantsecurity.ai/wp-content/uploads/2026/03/malicious-Stroke.svg) Recommended Malicious

#### Suspicious VPN login bypassed MFA on registered device

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon-source.svg) Escalate to Case

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon987.svg)

##### Classification

#### Anomalous VPN Login

Employee's account was accessed from an unfamiliar location behind a consumer VPN — MFA challenges failed three times, and no ZTNA client was found on their registered device.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon987.svg)

##### Classification

#### Anomalous VPN Login

Employee's account was accessed from an unfamiliar location behind a consumer VPN — MFA challenges failed three times, and no ZTNA client was found on their registered device.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon765.svg)

##### Planning and Execution

#### AI triage findings

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/7868767logo-source.svg) ![](https://radiantsecurity.ai/wp-content/uploads/2026/04/2kjhlogo-source.svg) ![](https://radiantsecurity.ai/wp-content/uploads/2026/04/76dkulogo-source.svg)

**Is the login IP associated with a VPN or anonymizing service?**

The IP resolves to an ExpressVPN exit node in Iceland — absent from this user's entire login history.

**Did the user successfully complete MFA during this login?**

MFA failed three times — session access was granted via a legacy authentication fallback policy.

**Is a VPN client installed on the user's registered endpoint?**

No VPN client is installed on the registered device — confirming the VPN traffic originated elsewhere.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon54654.svg)

##### Enrichment

#### Involved artifacts

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector-Stroke.svg) blastlabs-secure-login.com

authenticated via desktop browser

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector-Stroke.svg) Remote Azure AD — MFA: Failed

originating from commercial VPN exit node

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector45Stroke.svg) 104.223.87.34 (Reykjavik, Iceland)

flagged against registered device baseline

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector876Stroke.svg) srodriguez-DELL-WIN11

with prior clean login pattern from expected location

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector45Stroke.svg) 76.102.44.19 (Austin, Texas)

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon65765.svg)

##### Response

#### Take action

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/pause-icon-source.svg)

##### Suspend user account

#### Microsoft Entra ID

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/jkicon.svg)

##### Terminate active sessions

#### Microsoft Entra ID

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/lklk8icon.svg)

##### Force MFA re-enrollment

#### Microsoft Entra ID

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/cjlkjicon.svg)

##### ![](https://radiantsecurity.ai/wp-content/uploads/2026/03/malicious-Stroke.svg) Recommended Malicious

#### Persistent web attack bypassed WAF and reached application

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon-source.svg) Escalate to Case

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon987.svg)

##### Classification

#### External SQL injection

An external attacker cycled through evasion techniques across dozens of blocked attempts until a modified SQL injection payload slipped past WAF rules and hit Blast Labs' application layer.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon987.svg)

##### Classification

#### External SQL injection

An external attacker cycled through evasion techniques across dozens of blocked attempts until a modified SQL injection payload slipped past WAF rules and hit Blast Labs' application layer.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon765.svg)

##### Planning and Execution

#### AI triage findings

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/elogo-source.svg) ![](https://radiantsecurity.ai/wp-content/uploads/2026/04/wljklogo-source.svg)

**Analyze requests from this IP in the last 30 days.**

47 requests were sent and blocked over 11 minutes before the 48th attempt evaded detection.

**Is this IP associated with known malicious or anonymizing infrastructure?**

The IP is a confirmed Tor exit node with a history of automated web application attacks.

**Did the successful request cause anomalous behavior in the application or database?**

The request returned an HTTP 500 error, indicating the payload reached and interacted with the backend.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon54654.svg)

##### Enrichment

#### Involved artifacts

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector45Stroke.svg) 185.220.101.34

repeatedly targeted

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/ljkicon-source.svg) https://portal...com/api/v2/auth

with escalating attack technique

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/ljficon-source.svg) SQL Injection—WAF Evasion Variant

blocked across 47 attempts by

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/fjlkjicon.svg) SQLi-Detection-Rule-09

until modified payload triggered response

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector45Stroke.svg) write → failure (HTTP 500)

exposing backend

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector45Stroke.svg) portal.blastlabs.com

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon65765.svg)

##### Response

#### Take action

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/wicon.svg)

##### Block attacker IP

#### Imperva Cloud WAF

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/3werfgblocks.svg)

##### Escalate to incident response

#### PagerDuty

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/hlkjfreplace.svg)

##### Patch bypassed WAF rule

#### Imperva Cloud WAF

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/kjhkjh97icon.svg)

##### ![](https://radiantsecurity.ai/wp-content/uploads/2026/04/romb-icon.svg) Recommended Malicious

#### Persistent web attack bypassed WAF and reached application

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon-source.svg) Mark Benign

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon987.svg)

##### Classification

#### Low-Fidelity Outbound Alert

A corporate device triggered a network alert for unusual outbound traffic patterns — flagged by firewall rules as potentially suspicious but lacking clear indicators of <br> malicious intent.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon987.svg)

##### Classification

#### Low-Fidelity Outbound Alert

A corporate device triggered a network alert for unusual outbound traffic patterns — flagged by firewall rules as potentially suspicious but lacking clear indicators of <br> malicious intent.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon765.svg)

##### Planning and Execution

#### AI triage findings

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/data-lkjsources.svg) ![](https://radiantsecurity.ai/wp-content/uploads/2026/04/7868767logo-source.svg)

**Is the destination IP or domain associated with any known threats?**

Domain resolves to a verified Google infrastructure endpoint with no threat associations.

**Has this device shown any signs of compromise or suspicious process activity?**

No malicious processes, file executions, or behavioral anomalies detected on the device.

**Has this device communicated with this destination before?**

The device has made repeated connections to this domain over the past 90 days — consistent with normal usage.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon54654.svg)

##### Enrichment

#### Involved artifacts

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector876Stroke.svg) srodriguez@blastlabs.com

generated outbound traffic to

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector45Stroke.svg) 142.250.80.46 — Google LLC, US

associated with external domain

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector45Stroke.svg) clients6.google.com

triggered firewall policy

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/fjlkjicon.svg) Outbound-Anomaly-Low-Confidence-Rule-447

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/jhkjh8icon.svg)

##### Response

#### Take action

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/fhicon.svg)

##### Close alert as benign

#### Palo Alto Networks

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/jhkhicon.svg)

##### Tune low-fidelity rule

#### Palo Alto Networks

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/iot-icon.svg)

##### ![](https://radiantsecurity.ai/wp-content/uploads/2026/04/romb-icon.svg) Recommended Malicious

#### Authorized engineer scan flagged as OT reconnaissance activity

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon-source.svg) Mark Benign

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon987.svg)

##### Classification

#### Potential reconnaissance

A scheduled OT diagnostic scan triggered a Dragos reconnaissance alert — Radiant confirmed the activity was authorized, change-ticket approved, and identical in pattern to scans run by the same engineer the month prior.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon987.svg)

##### Classification

#### Potential reconnaissance

A scheduled OT diagnostic scan triggered a Dragos reconnaissance alert — Radiant confirmed the activity was authorized, change-ticket approved, and identical in pattern to scans run by the same engineer the month prior.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon765.svg)

##### Planning and Execution

#### AI triage findings

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/7868767logo-source.svg) ![](https://radiantsecurity.ai/wp-content/uploads/2026/04/23logo-source.svg) ![](https://radiantsecurity.ai/wp-content/uploads/2026/04/data-lkjsources.svg)

**Has this user performed identical OT scanning activity before?**

Matching scan patterns from the same user and device were recorded during last month's maintenance window.

**Is the tool used for scanning recognized and approved by the security team?**

Nmap 7.94 is on the approved diagnostic tooling list and carries a valid code signature.

**Has this device communicated with this destination before?**

The device has made repeated connections to this domain over the past 90 days — consistent with normal usage.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon54654.svg)

##### Enrichment

#### Involved artifacts

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector-Stroke.svg) rpalmer@blastlabs.com

logged into corporate engineering workstation

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector876Stroke.svg) rpalmer-DELL-WIN11

ran authorized network diagnostic tool

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/87687vjhvjvicon.svg) Nmap 7.94 — code-signed

approved scanning OT network segment from

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector45Stroke.svg) 10.0.12.45 - internal

corporate LAN sweeping known OT asset range

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector45Stroke.svg) 10.0.12.45:49152

reaching industrial control assets

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector876Stroke.svg) PLC-HVAC-CTRL-07

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/jhkjh8icon.svg)

##### Response

#### Take action

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/fhicon.svg)

##### Close alert as benign

#### Dragos

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/987icon.svg)

##### Log authorized scan activity

#### ServiceNow

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/jhkhicon.svg)

##### Tune OT reconnaissance detection rule

#### Dragos

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/aws-icon.svg)

##### ![](https://radiantsecurity.ai/wp-content/uploads/2026/03/malicious-Stroke.svg) Recommended Malicious

#### Compromised API credentials exploited misconfigured S3 bucket

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon-source.svg) Escalate to Case

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon987.svg)

##### Classification

#### Compromised API Credentials

A production service account's API credentials were used from a Tor exit node to enumerate and access S3 buckets — actions outside the account's normal behavior, due to a misconfigured public-read access policy that was never remediated.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon987.svg)

##### Classification

#### Compromised API Credentials

A production service account's API credentials were used from a Tor exit node to enumerate and access S3 buckets — actions outside the account's normal behavior, due to a misconfigured public-read access policy that was never remediated.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon765.svg)

##### Planning and Execution

#### AI triage findings

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/data-sources.svg)

**Are the API actions consistent with this service account's normal behavior?**

This account has never previously performed bucket enumeration or cross-resource object reads.

**Is the accessed S3 bucket misconfigured or overly permissive?**

The bucket had a public-read ACL applied — granting access far beyond the service account's intended scope.

**Was any data successfully read from the exposed bucket?**

2,418 API read calls completed successfully across multiple file types before the session was flagged.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon54654.svg)

##### Enrichment

#### Involved artifacts

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/robot-icon.svg) blastlabs-prod-svc-dataops

API credentials used anomalously from external IP

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector45Stroke.svg) 197.231.221.211

authenticating to AWS production environment

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/icon-source.svg) BlastLabs-Prod-us-east1

accessing sensitive production storage

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/icon-source.svg) s3://blastlabs-prod-customer-data

exposed due to misconfigured access policy

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector-Stroke.svg) s3:GetObject — Scope: public-read (misconfigured ACL)

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon65765.svg)

##### Response

#### Take action

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/rew-icon.svg)

##### Rotate API credentials

#### AWS IAM

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/jkicon.svg)

##### Restrict bucket ACL

#### AWS S3

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/stop-icon-source.svg)

##### Block IP

#### AWS WAF

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/insider-icon.svg)

##### ![](https://radiantsecurity.ai/wp-content/uploads/2026/03/malicious-Stroke.svg) Recommended Malicious

#### High-risk user accessing sensitive resources before likely departure

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon-source.svg) Escalate to Case

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon987.svg)

##### Classification

#### Pre-Departure Data Gathering

An employee was observed accessing authorized but infrequently used sensitive resources over a 30-day period — a pattern consistent with pre-departure data gathering, corroborated by repeated job site visits and personal Gmail upload activity.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon987.svg)

##### Classification

#### Pre-Departure Data Gathering

An employee was observed accessing authorized but infrequently used sensitive resources over a 30-day period — a pattern consistent with pre-departure data gathering, corroborated by repeated job site visits and personal Gmail upload activity.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon765.svg)

##### Planning and Execution

#### AI triage findings

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/7868767logo-source.svg) ![](https://radiantsecurity.ai/wp-content/uploads/2026/04/jkllogo-source.svg) ![](https://radiantsecurity.ai/wp-content/uploads/2026/04/ljlogo-source.svg)

**Has this user's Exabeam risk score changed significantly in the past 30 days?**

Risk score escalated from 21 to 94 over 30 days — driven by access anomalies and behavioral drift.

**Which resources did the user access that were authorized but outside their normal patterns?**

User accessed internal pricing models and contract templates not touched in the prior 12 months.

**Has the user shown any signs of data staging or unusual file activity recently?**

Large volumes of internal documents were opened and copied to a local folder in the past two weeks.

**Has the user uploaded or transferred any files to external services recently?**

Several file transfers to personal Gmail were detected via browser upload in the past 10 days.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon54654.svg)

##### Enrichment

#### Involved artifacts

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector-Stroke.svg) Marcus Wilson — Sr Solutions Engineer

Authenticating as

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector-Stroke.svg) mwilson@blastlabs.com

accessed sensitive internal files

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/87879icon.svg) 2024-Enterprise-Pricing-Model.xlsx

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/87879icon.svg) Master-Services-Agreement.docx

from managed corporate device

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector876Stroke.svg) mwilson-DELL-WIN11

with browser activity across job search platforms

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector45Stroke.svg) linkedin.com/jobs

alongside repeated file transfers to personal email

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/7786jhkjhicon.svg) Gmail — mail.google.com

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon65765.svg)

##### Response

#### Take action

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/kejh338icon.svg)

##### Suspend user account

#### Okta

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/jkicon.svg)

##### Revoke active sessions

#### Okta

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/bell-icon.svg)

##### Notify HR and legal team

#### ServiceNow

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/siem-icon.svg)

##### ![](https://radiantsecurity.ai/wp-content/uploads/2026/03/malicious-Stroke.svg) Recommended Malicious

#### Splunk detected quarterly report executed outside authorized reporting window

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon-source.svg) Escalate to Case

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon987.svg)

##### Classification

#### Stale Permission Abuse

A former FP&A analyst ran a restricted quarterly earnings report in the ERP system outside its authorized window — using elevated permissions that were never revoked after they changed roles.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon987.svg)

##### Classification

#### Stale Permission Abuse

A former FP&A analyst ran a restricted quarterly earnings report in the ERP system outside its authorized window — using elevated permissions that were never revoked after they changed roles.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon765.svg)

##### Planning and Execution

#### AI triage findings

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/2kjhlogo-source.svg) ![](https://radiantsecurity.ai/wp-content/uploads/2026/04/uyulogo-source.svg)

**Does this user still hold a role requiring access to this report?**

The user left the FP&A team four months ago and no longer holds a financial reporting role.

**Has this user run this report before?**

The report was run twice before — both times within authorized Q3 and Q4 reporting windows.

**Was the timing of this execution consistent with the user's normal behavior?**

Execution occurred at 11:47 PM — outside business hours and inconsistent with all prior activity.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon54654.svg)

##### Enrichment

#### Involved artifacts

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector-Stroke.svg) lfortier@blastlabs.com

executed sensitive financial report

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/7786jhkjhicon.svg) SAP ERP

running restricted report at anomalous time

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector45Stroke.svg) QTR-EARNINGS-CONSOLIDATED

using permissions that should have been revoked

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector-Stroke.svg) SAP Role — Status: Active (stale)

from corporate device during off-hours

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector876Stroke.svg) lfortier-LENOVO-WIN11

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon65765.svg)

##### Response

#### Take action

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/kejh338icon.svg)

##### Suspend user account

#### Okta

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/eicon.svg)

##### Notify finance team

#### ServiceNow

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/lkj-icon.svg)

##### Preserve audit logs

#### Splunk

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/supply-icon.svg)

##### ![](https://radiantsecurity.ai/wp-content/uploads/2026/03/malicious-Stroke.svg) Recommended Malicious

#### Vulnerable library executed and communicating with C2 server

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon-source.svg) Escalate to Case

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon987.svg)

##### Classification

#### Vulnerable Library Executed

A known-vulnerable third-party library was committed to the production codebase and subsequently executed on a developer endpoint - establishing an outbound connection to a confirmed malicious command-and-control server.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon987.svg)

##### Classification

#### Vulnerable Library Executed

A known-vulnerable third-party library was committed to the production codebase and subsequently executed on a developer endpoint - establishing an outbound connection to a confirmed malicious command-and-control server.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon765.svg)

##### Planning and Execution

#### AI triage findings

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/87uhjlogo-source.svg) ![](https://radiantsecurity.ai/wp-content/uploads/2026/04/7868767logo-source.svg) ![](https://radiantsecurity.ai/wp-content/uploads/2026/04/data-lkjsources.svg)

**Is the flagged library version associated with any known vulnerabilities?**

lodash 4.17.15 is confirmed vulnerable to CVE-2026-23337, a critical command injection flaw.

**Was the vulnerable library executed on a developer endpoint after commit?**

The library executed via a Node.js process on dchen's corporate MacBook within 4 hours of commit.

**Did the executing process make any outbound network connections?**

The process established an outbound HTTPS connection to cdn-pkg-delivery[.]io, a confirmed C2 domain.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon54654.svg)

##### Enrichment

#### Involved artifacts

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector-Stroke.svg) dchen@blastlabs.com

committed third-party library to production repo

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/87879icon.svg) lodash-4.17.15.min.js-SHA256:a1...

containing known critical vulnerability

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/kjhhjicon.svg) CVE-2026-23337 — Command Inject...

library executed on developer workstation

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector876Stroke.svg) chen-MacBook-Pro-M2

spawning suspicious outbound process

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/87687vjhvjvicon.svg) node.js → lodash-4.17.15.min.js

establishing connection to malicious external server

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector45Stroke.svg) 10.0.4.31:52847→91.212.166.21:443

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon65765.svg)

##### Response

#### Take action

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/3werfgblocks.svg)

##### Isolate developer endpoint

#### CrowdStrike Falcon

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/stop-icon-source.svg)

##### Block malicious domain

#### Palo Alto Networks

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/rew-icon.svg)

##### Open ticket - rotate keys and undo code changes

#### Jira

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/rewert-icon.svg)

##### ![](https://radiantsecurity.ai/wp-content/uploads/2026/03/malicious-Stroke.svg) Recommended Malicious

#### Executive impersonation attempt targetting finance team

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon-source.svg) Escalate to Case

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon987.svg)

##### Classification

#### Executive Impersonation Attempt

A employee-reported email was confirmed as a targeted business email compromise (BEC) attempt — originating from a spoofed executive domain registered three days prior and deliberately composed in Spanish to evade English-language detection controls.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon987.svg)

##### Classification

#### Executive Impersonation Attempt

A employee-reported email was confirmed as a targeted business email compromise (BEC) attempt — originating from a spoofed executive domain registered three days prior and deliberately composed in Spanish to evade English-language detection controls.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon765.svg)

##### Planning and Execution

#### AI triage findings

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/wlogo-source.svg) ![](https://radiantsecurity.ai/wp-content/uploads/2026/04/jklbhlogo-source.svg) ![](https://radiantsecurity.ai/wp-content/uploads/2026/04/78yujlogo-source.svg)

**Is the sender domain a lookalike impersonating Blast Labs?**

Blastlabs-finance.com was registered 3 days ago with no affiliation to any legitimate Blast Labs domain.

**Has the targeted employee received prior emails from this domain?**

Two emails from the same domain reached tnavarro's inbox in the past 5 days — both unopened.

**Does the email contain indicators of wire fraud intent?**

The email demands an urgent $84,000 wire transfer to an overseas account, written entirely in Spanish.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon54654.svg)

##### Enrichment

#### Involved artifacts

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/mail-icon.svg) dchen@blastlabs.com

and sent from spoofed address

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector45Stroke.svg) cfo-office@blastlabs-finance.com

impersonating legitimate executive

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector-Stroke.svg) Diego Santiago — CFO, Blast Labs

targeting finance team employee

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector-Stroke.svg) tnavarro@blastlabs.com

delivered through external mail infrastructure

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector45Stroke.svg) 185.234.219.44 (Bucharest,Romania)

routed via lookalike domain registered 3 days ago

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector45Stroke.svg) blastlabs-finance.com

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon65765.svg)

##### Response

#### Take action

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/wicon.svg)

##### Block sender domain

#### Microsoft Defender for Office 365

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/3werfgblocks.svg)

##### Quarantine all emails

#### Microsoft Defender for Office 365

![](https://radiantsecurity.ai/wp-content/uploads/2026/04/qicon.svg)

##### Submit domain for takedown

#### ZeroFox

## What security leaders say?

From the first day of the POC, Radiant was catching things our MSSP was missing. Their platform is the most accurate agentic SOC we’ve seen, with investigations going significantly deeper than anything else we looked at.

Brian Rowe

Vice President Information Technology

![](https://radiantsecurity.ai/wp-content/uploads/2026/02/Brian-Rowe.webp)

Most organizations can bring their SOC in-house today thanks to AI SOC. Validating alerts is simpler than it used to be, and pulling log data into a single view means you're not searching through multiple systems.

Rodney Stewart

Infrastructure Engineering and Security Manager

![](https://radiantsecurity.ai/wp-content/uploads/2026/02/Video-Container-2.webp)

“Radiant Security consistently goes above and beyond to adapt to our specific security needs, their leadership team is closely involved, and every custom request is taken seriously and delivered in a short time”

Josh Lanners

Director, IT Ops and Security

![](https://radiantsecurity.ai/wp-content/uploads/2026/01/Video-Container.webp)

“Radiant cuts through the ambiguity of traditional managed security. It provides the deep context and speed we need, often alerting us to threats well before a manned SOC. Getting detailed, correlated information in a sensible manner, and getting it quickly, makes my job a lot easier.”

Rob Boyd

Manager of information security

![](https://radiantsecurity.ai/wp-content/uploads/2026/02/Group1707480925.webp)

“Thanks to Radiant, we can now focus on our customer's real threats instead of drowning in alert noise.”

Gregory Morawietz

Owner

"Our mean time to detect is 10X better than the industry average, and our mean time to respond is 2X better. We're saving between 200-300 hours a month.

![Michael_Butler](https://radiantsecurity.ai/wp-content/uploads/2023/08/Michael_Butler-150x150.jpg)

Michael Butler

Director of Information Security Operations

”As much as I would like to keep Radiant a secret for my own competitive advantage, I would definitely recommend it to any MSSP who is serious about their cybersecurity.”

Grigoriy Milis

CIO

## Additional resources

[![Radiant’s yellow mascot and a security analyst sit within a pink circular feedback loop icon, representing how analyst input trains and refines AI-SOC detections over time.](https://radiantsecurity.ai/wp-content/uploads/2025/11/Blog-_-Feedback-Loops-Image-Only-1.png)

AI

### Continuous feedback loops: Why training your AI-SOC doesn’t stop at deployment

A pre-trained AI-SOC can perform on day one and fail by day ninety. Static models can’t keep up with changing behavior or new threats. A continuously learning AI-SOC can. This article shows how feedback loops turn AI into a true member of the team.

![](https://radiantsecurity.ai/wp-content/uploads/2023/03/avatar_user_4_1680018553.png)

Shahar Ben-Hador

Nov 10, 2025 | 15 min read](https://radiantsecurity.ai/blog/continuous-feedback-loops/)

[![](https://radiantsecurity.ai/wp-content/uploads/2025/11/Blog-Cover-What-happens-to-MSSPs-and-MDRs.png)

AI

### What happens to MSSPs and MDRs in the age of the Al-SOC?

MSSPs and MDRs filled a gap, but AI-SOC platforms now let security teams bring more capability in-house. This article explores how AI-driven triage and correlation change cost, visibility, and response for organizations reconsidering managed security.

![](https://radiantsecurity.ai/wp-content/uploads/2023/03/avatar_user_4_1680018553.png)

Shahar Ben-Hador

Nov 3, 2025 | 9 min read](https://radiantsecurity.ai/blog/mssps-and-mdrs-al-soc/)

[![](https://radiantsecurity.ai/wp-content/uploads/2025/12/Can-your-SOC-save-you-Blog.png)

Expert Content

### When your $2M security detection fails: Can your SOC save you?

When your $2M in detection tools inevitably fail, your SOC is the only thing standing between a missed alert and a catastrophic breach. Without a strong last line of defense, you're leaving the door wide open to threats that detection was never actually built to catch.

![](https://radiantsecurity.ai/wp-content/uploads/2023/03/avatar_user_4_1680018553.png)

Shahar Ben-Hador

Dec 2, 2025 | 6 min read](https://radiantsecurity.ai/blog/can-soc-save-you/)
