Network Activity Monitor
● Live · Sensor: NET-SENSOR-CORE-01 · Interface: eth0 · 10Gbps
Inbound Traffic
Peak: 7.4 Gbps at 14:22
↑ 23% vs baseline
Outbound Traffic
Normal range: 0.8–2.1 Gbps
↑ 8% vs baseline
Active Connections
312 flagged suspicious
↑ 1,204 in last 5min
Anomaly Score
Threshold: 60 · Status: ALERT
↑ 18pts — elevated
Blocked Threats
847 unique source IPs
↑ 347 in last hour
Bandwidth Utilization
Last 60 minutes · 5-min intervals · Gbps
Protocol Distribution
By traffic volume %
Active Connections
6 flagged| Source IP | Src Port | Destination IP | Dst Port | Protocol | Bytes | Duration | Geo | Risk Score | Status | Actions |
|---|---|---|---|---|---|---|---|---|---|---|
| 10.0.1.55 | 54821 | 91.92.251.103 | 443 | HTTPS | 14.2 MB | 00:12:44 | 🇷🇺 Moscow, RU | 94 | Suspicious | |
| 10.0.2.34 | 49234 | 185.220.101.47 | 22 | SSH | 2.1 KB | 00:00:08 | 🇩🇪 Frankfurt, DE | 87 | Blocked | |
| 10.0.1.112 | 63441 | 172.217.14.46 | 443 | HTTPS | 847 KB | 00:04:12 | 🇺🇸 Mountain View, US | 12 | Normal | |
| 10.0.3.78 | 51023 | 8.8.8.8 | 53 | DNS | 4.8 KB | 00:00:01 | 🇺🇸 Anycast, US | 8 | Normal | |
| 10.0.1.23 | 44129 | 45.142.212.100 | 443 | HTTPS | 3.4 MB | 00:07:33 | 🇳🇱 Amsterdam, NL | 78 | Suspicious | |
| 10.0.2.89 | 52881 | 10.0.1.15 | 445 | SMB | 128 MB | 00:22:11 | 🏠 Internal | 82 | Suspicious | |
| 10.0.1.34 | 48823 | 104.21.4.147 | 443 | HTTPS | 1.2 MB | 00:02:44 | 🇺🇸 San Francisco, US | 18 | Normal | |
| 10.0.4.11 | 57443 | 193.32.162.48 | 80 | HTTP | 88 KB | 00:00:34 | 🇷🇺 St. Petersburg, RU | 61 | Suspicious | |
| 10.0.2.67 | 43201 | 151.101.1.140 | 443 | HTTPS | 3.8 MB | 00:09:02 | 🇺🇸 Fastly CDN, US | 5 | Normal | |
| 10.0.1.88 | 60012 | 77.88.21.3 | 443 | HTTPS | 22 MB | 00:31:08 | 🇷🇺 Moscow, RU | 91 | Suspicious |
Anomaly / IDS Alerts
Data Exfiltration
ET-EXFIL-2847Unusual outbound volume from 10.0.1.55 → 91.92.251.103. 14.2 MB in 12 min.
Port Scan Detected
ET-SCAN-0044185.220.101.47 scanned 4,200 ports in 8 seconds from external.
SMB Lateral Movement
ET-LATERAL-1192Internal SMB traffic spike: 10.0.2.89 → 10.0.1.15. 128 MB transferred.
DNS Tunneling
ET-DNS-TUNNEL-0018High-entropy DNS TXT queries from 10.0.1.23. Avg query length: 187 chars.
Beaconing Pattern
ET-C2-BEACON-0337Regular 300s interval connections from 10.0.1.88 → 77.88.21.3:443.
Firewall Event Log
Last 500 events| Time | Rule ID | Action | Source IP | Src Port | Dest IP | Dst Port | Proto | Reason | Hit Count |
|---|---|---|---|---|---|---|---|---|---|
| 14:51:14 | FW-DENY-4821 | DENY | 🇩🇪 185.220.101.47 | — | 10.0.1.15 | 22 | TCP | Blacklisted IP — TOR Exit Node | 2,847 |
| 14:51:09 | FW-DENY-3301 | DENY | 🇷🇺 91.92.251.103 | — | 10.0.0.1 | 3389 | TCP | RDP from external — policy violation | 14 |
| 14:50:58 | FW-ALLOW-0012 | ALLOW | 🇺🇸 10.0.1.55 | 54821 | 172.217.14.46 | 443 | TCP | Outbound HTTPS — corporate policy | 1 |
| 14:50:44 | FW-DROP-9182 | DROP | 🇳🇱 45.142.212.100 | — | 10.0.2.0/24 | 445 | TCP | External SMB attempt — blocked | 388 |
| 14:50:31 | FW-DENY-7744 | DENY | 🇷🇺 193.32.162.48 | — | 10.0.1.88 | 80 | TCP | Known C2 infrastructure IP | 72 |
| 14:50:18 | FW-ALLOW-0008 | ALLOW | 🇺🇸 10.0.3.22 | 49821 | 8.8.8.8 | 53 | UDP | DNS resolution — allowed | 1 |
| 14:50:02 | FW-DROP-6612 | DROP | 🇷🇺 77.88.21.3 | — | 10.0.0.0/8 | 4444 | TCP | Metasploit default port — blocked | 19 |
| 14:49:47 | FW-DENY-2291 | DENY | 🇨🇳 103.27.124.88 | — | 10.0.1.1 | 161 | UDP | SNMP from untrusted zone | 44 |