SOC Dashboard

Real-time security operations center for AI systems

Active Incidents

12

3 vs last hour

Critical Incidents

4

1 vs last hour

High Risk Agents

8

2 vs last hour

Security Events

1,842

18% vs last hour

Blocked Actions

312

24% vs last hour

Active Sessions

27

8 vs last hour

1. Live Attack Timeline

CriticalHighMediumLowInfo
  • Prompt Injection
  • Data Exfiltration
  • Tool Misuse
  • Unauthorized Access
  • Other

2. Active Incidents

IncidentSeverityStatus

Prompt Injection & Data Access Attempt

INC-2025-00487 · CustomerSupportAgent · 11:05 AM

CriticalInvestigating

Unauthorized File Access

INC-2025-00483 · DataAnalystAgent · 11:02 AM

HighInvestigating

Tool Misuse: SQL Execution

INC-2025-00481 · ReportBuilderAgent · 10:59 AM

HighNew

Data Exfiltration Attempt

INC-2025-00476 · ResearchAgent · 10:52 AM

MediumInvestigating

Excessive API Usage

INC-2025-00472 · InsightsAgent · 10:48 AM

MediumMonitoring

3. Threat Heat Map

  • Low
  • Medium
  • High
  • Critical

4. Agent Graph

Orchestrator Agent
CustomerSupportAgentRisk: High
FinanceAgentRisk: High
ResearchAgentRisk: Medium
RepoAssistAgentRisk: Low
ReportBuilderAgentRisk: High

5. Tool Usage (Top 10)

Last 1 Hour

  • get_user_profile342 18%
  • search_knowledge_base289 24%
  • sql_query156 32%
  • document_retrieval134 11%
  • send_email98 5%
  • export_data76 41%
  • file_read63 17%
  • api_request58 19%
  • web_search44 12%
  • code_executor31 15%

6. Identity Risk

IdentityRiskActivity

jane.doe@acme.com

92 · CriticalAnomalous data access

svc-data-analyst

78 · HighExcessive tool usage

alex.smith@acme.com

64 · HighMultiple failed guardrails

research.bot@acme.com

48 · MediumNew tool usage

mike.johnson@acme.com

28 · LowNormal activity

7. Response Actions

Last 1 Hour

TimeActionIncidentStatus
11:12:45 AMBlock RequestINC-2025-00487Success
11:07:32 AMDisable Tool (sql_query)INC-2025-00483Success
11:03:18 AMAlert SOCINC-2025-00481Success
11:01:55 AMIsolate SessionINC-2025-00476Success
10:58:40 AMRequire ApprovalINC-2025-00472Pending

8. MITRE ATT&CK Mapping

TacticTechniqueActiveTrend
Initial AccessT1611 - AI Model Prompt Injection4 33%
ExecutionT1059 - Command & Script Execution2 20%
PersistenceT1547 - AI Agent Persistence1 100%
Privilege EscalationT1622 - Tool Permission Abuse2 50%
Defense EvasionT1562 - Impair Defenses (Guardrails)3 25%
Credential AccessT1552 - Unsecured Credentials1 50%
DiscoveryT1620 - AI System Discovery3 17%
ExfiltrationT1041 - Exfiltration Over Web Channel1 100%

9. AI Recommendations

  • high

    Enable stricter guardrails for sql_query tool

    This tool is associated with 3 high-severity incidents.

  • high

    Review permissions for jane.doe@acme.com

    User has triggered multiple critical incidents.

  • medium

    Implement human approval for export_data

    High data exfiltration risk detected.

  • low

    Update knowledge base access policy

    Reduce exposure to sensitive documents.