Step 2 · Command center
Incident Commander
A single operating picture: severity, blast radius, the business clock, and the live state of every containment decision.
Severity
Critical
provisional classification
Blast radius
100
3 identities · 5 assets
Payroll run
—
business deadline
Decisions in flight
0
4 evidence items to preserve
Agentic analysis
—
Situation
CriticalAnomalous PowerShell on a finance endpoint owned by a user with privileged access to payroll and payment systems. Correlated with failed logins from an unusual geography, a suspicious mailbox forwarding rule, and possible lateral movement to a shared finance file server. Payroll processing is scheduled in approximately six hours.
Identities
3
Assets
5
Services
3
Evidence
4