2
Critical
2
High
1
Medium
0
Low
3
Open
1
Investigating
1
Resolved
Lateral Movement: SSH from SASE to K8s Pod
criticalAlert ID: ALT-001 • 12/6/2025, 10:00:00 AM
open
Source
alice.admin@lawfirm.com (192.168.1.50)
Destination
payroll-db-0 (10.0.2.15:22)
MITRE ATT&CK
T1021.004UnassignedFlow: Cabc12345
Data Exfiltration: Large Egress to Unknown IP
criticalAlert ID: ALT-002 • 12/6/2025, 9:15:00 AM
investigating
Source
test-app-xyz99 (10.0.5.10)
Destination
203.0.113.50:443
MITRE ATT&CK
T1041john.doe@company.comFlow: Cjkl31415
DNS Tunneling: High Entropy DNS Queries
highAlert ID: ALT-003 • 12/6/2025, 9:30:00 AM
open
Source
payment-processor-abc12 (10.0.2.25)
Destination
8.8.8.8:53
MITRE ATT&CK
T1071.004UnassignedFlow: Cghi11121
East-West: Frontend Direct to Database
highAlert ID: ALT-004 • 12/6/2025, 8:45:00 AM
open
Source
compromised-pod-abc (10.0.1.50)
Destination
postgres-primary-0 (10.0.4.100:5432)
MITRE ATT&CK
T1021.004UnassignedFlow: Cmno16171
Privileged Pod External Connection
mediumAlert ID: ALT-005 • 12/6/2025, 8:30:00 AM
resolved
Source
kube-system/calico-node-xyz (10.0.0.5)
Destination
198.51.100.10:443
MITRE ATT&CK
T1071.001jane.smith@company.comFlow: Cpqr18192