Identity activity
“Which privileged identities signed in from new locations?” Connect authentication behavior to privileges and related events.
Enterprise search, focused on security. Explore the telemetry and investigation context available to your team using natural-language questions.
Move from a user, indicator, or incident to the evidence that helps explain it. Search is grounded in connected security data and the scope available to the investigation.
The interactive examples show fixed sample answers. They do not query a live customer environment.
The sample identity signed in from an unfamiliar location, created an access key, and changed a sensitive resource policy. Privilege level and the sequence of activity increase the investigation priority.
In this sample timeline, a new access key was followed by a policy modification. Review the key’s permissions, identify the affected resource, and validate whether the changes were expected.
Related sign-in and cloud activity may indicate credential compromise. Scope is under review. Recommended next steps are owner validation, credential review, and analyst-approved containment if warranted.
“Which privileged identities signed in from new locations?” Connect authentication behavior to privileges and related events.
“Has this IP appeared in previous incidents?” Use available sightings and threat context to guide the next step.
“What should I investigate next?” Review the evidence, uncertainty, and recommended follow-up before acting.
Bring your security stack. We’ll explore how GuardNex AI can support the way your team detects, investigates, and responds.