The Investigation Insights – SpyCloud integration enables analysts to quickly get an understanding on if one of their employees has a risk of their accounts being taken over and enables them to quickly resolve anything if an employee is at risk.
The SpyCloud Employee Account Takeover Prevention enables enterprises to stay ahead of account takeover and targeted attacks like ransomware by detecting and resetting compromised passwords early, before criminals have a chance to use them.
Examples
SpyCloud Data Overview
- Summary Tags: When an analyst runs a search using the SpyCloud integration, they will instantly be able to tell the number of instances an email, domain or IP has been seen and the established severity of those instances. Allowing analysts to quickly know if there is something they should look into with SpyCloud.
- Link to SpyCloud: When drilling into the details of the SpyCloud integration, analysts are first presented with a link to pivot into SpyCloud for further investigation.
- Result Information: While also looking at the details of the SpyCloud integration analysts can see the associated results and who the users are and what severity risk they present.
