Example output

This is what lands in your queue.

Below is a complete Qvasir incident report — the artifact your team receives when the platform escalates. No triage happened before this: the correlation, entity resolution, investigation, and recommendations you see were produced by the system.

Illustrative example from a demonstration environment. All organizations, names, hosts, and IP addresses are fictional (reserved documentation ranges).
Incident INC-2026-0142 Severity High Opened 2026-08-14 03:22 UTC Escalated 2026-08-14 03:41 UTC (19 min after first signal) Status Awaiting analyst decision

Executive summary

A password-spray campaign from infrastructure linked to a known commodity botnet succeeded against one account (m.lindqvist) that lacked MFA enforcement. Within nine minutes, the actor authenticated from a previously unseen network, granted mailbox permissions to an unrecognized OAuth application, and created an inbox rule that forwards and hides finance-related mail — consistent with business-email-compromise staging. No lateral movement or data exfiltration beyond mail-rule creation has been observed in the covered sources.

Involved entities

user · m.lindqvist user · 14 additional targeted accounts (spray, all failed) idp · sso.corp.example oauth-app · "Mail Sync Utility" (unverified publisher) ip · 203.0.113.66 (spray origin) ip · 198.51.100.23 (post-compromise login)

Timeline

  • Password-spray pattern begins: 15 accounts, 1–2 attempts each, from 203.0.113.66. Individually below lockout thresholds. source: identity provider sign-in logs · detection: L2 aggregation
  • Successful authentication for m.lindqvist from 203.0.113.66. Account is in a legacy group without MFA enforcement. source: identity provider sign-in logs
  • Second session for the same account from 198.51.100.23 — geography and ASN with no prior association to this user in its entity history. source: identity provider sign-in logs · context: entity history & scoring
  • OAuth consent granted to application "Mail Sync Utility" (unverified publisher) with mail read/write scope. source: cloud audit log
  • Inbox rule created: forward messages matching finance keywords to external address, mark read, move to archive. source: mailbox audit log
  • Signals associated on entity m.lindqvist within scoring window — incident qualified and escalated. Qvasir association & scoring

Investigation (automated)

threat-intel · ip-reputation

203.0.113.66 is flagged by two intelligence sources as commodity credential-stuffing infrastructure (first reported 11 days ago). 198.51.100.23 has no prior reputation — consistent with a clean hand-off host after initial access.

dns · passive-lookup

Reverse and passive DNS on 198.51.100.23 show a hosting-provider netblock with short-lived tenant churn; no organizational infrastructure resolves there.

event-search · historical

90-day lookback: m.lindqvist has never authenticated from either ASN; no other account has interacted with OAuth app "Mail Sync Utility"; the 14 failed spray targets show no subsequent anomalous activity.

entity-history · scoring

No prior signals on this entity in the current window. The spray-success → new-network → consent-grant → inbox-rule sequence matches a staged BEC pattern rather than isolated anomalies.

MITRE ATT&CK® mapping

T1110.003 — Password Spraying T1078 — Valid Accounts T1550.001 — Application Access Token T1114.003 — Email Forwarding Rule T1564.008 — Email Hiding Rules

Recommendations

  1. Contain now: revoke all active sessions and reset credentials for m.lindqvist; revoke the OAuth grant for "Mail Sync Utility" and block the publisher.
  2. Remove persistence: delete the inbox rule; review sent items and forwarded mail since 03:31 UTC for exposure.
  3. Close the gap: enforce MFA on the legacy account group — 14 additional accounts in this group were targeted in the same spray.
  4. Watch: a monitoring rule for new consents to unverified OAuth publishers has been drafted from this incident and is ready for review and deployment.
Full audit trail — every detection, association, agent step, and tool call above is individually logged and reviewable in the platform.