Daily reports Postilion
Alarms - A05W063                                   from: 2018-07-25       to: 2018-07-25
                                                   No Alarms Found for A05W063
                                   Alarms - A05L020                                   from: 2018-07-25       to: 2018-07-25
                                                    No Alarms Found for A05L020
                                   Alarms - A05W067                                   from: 2018-07-25       to: 2018-07-25
 Alarm                                                        Risk           Source                  Destination
 Environmental Awareness - Suspicious Behaviour - Account       2           A05W067                      A05W067
 Lockout (1 events)
 Environmental Awareness - Suspicious Behaviour - Account       2           A05W067                      A05W067
 Lockout (1 events)
                                   Alarms - A05W068                                   from: 2018-07-25       to: 2018-07-25
                                                   No Alarms Found for A05W068
                                   Alarms - A05W069                                   from: 2018-07-25       to: 2018-07-25
 Alarm                                                        Risk           Source                  Destination
 Delivery & Attack - Bruteforce Authentication - Cisco ACS      1           A05W069                       0.0.0.0
 (9 events)
                                   Alarms - A05W070                                   from: 2018-07-25       to: 2018-07-25
                                                   No Alarms Found for A05W070
                                   Alarms - A05L015                                   from: 2018-07-25       to: 2018-07-25
                                                    No Alarms Found for A05L015
                                   Alarms - A05L016                                   from: 2018-07-25       to: 2018-07-25
                                                    No Alarms Found for A05L016
                                   Alarms - A05L017                                   from: 2018-07-25       to: 2018-07-25
                                                    No Alarms Found for A05L017
User: admin / 2018-07-26 07:18:36                                                                                    Page 1 / 7
                                                                                      Daily reports Postilion
                                 Alarms - A05L019                                   from: 2018-07-25      to: 2018-07-25
                                                No Alarms Found for A05L019
                                  Alarms - a03l020                                  from: 2018-07-25      to: 2018-07-25
                                                 No Alarms Found for a03l020
                                 Alarms - A05W065                                   from: 2018-07-25      to: 2018-07-25
                                                No Alarms Found for A05W065
                                 Alarms - I05W002                                   from: 2018-07-25      to: 2018-07-25
 Alarm                                                      Risk          Source                   Destination
 Environmental Awareness - Suspicious Behaviour - Account    2            I05W002                      I05W002
 Lockout (1 events)
                                 Alarms - I05L001                                   from: 2018-07-25      to: 2018-07-25
                                                 No Alarms Found for I05L001
                                 Alarms - I05L002                                   from: 2018-07-25      to: 2018-07-25
                                                 No Alarms Found for I05L002
                                 Alarms - I05L000                                   from: 2018-07-25      to: 2018-07-25
                                                 No Alarms Found for I05L000
                                 Alarms - I05W003                                   from: 2018-07-25      to: 2018-07-25
                                                No Alarms Found for I05W003
                                 Alarms - A01W031                                   from: 2018-07-25      to: 2018-07-25
                                                No Alarms Found for A01W031
                                 Alarms - A01W024                                   from: 2018-07-25      to: 2018-07-25
                                                No Alarms Found for A01W024
User: admin / 2018-07-26 07:18:36                                                                                 Page 2 / 7
                                                                                          Daily reports Postilion
                                    Alarms - A00W195                                    from: 2018-07-25       to: 2018-07-25
 Alarm                                                          Risk         Source                    Destination
 Delivery & Attack - Bruteforce Authentication - Cisco ACS        1          A00W195                        0.0.0.0
 (12 events)
 Delivery & Attack - Bruteforce Authentication - Cisco ACS        1          A00W195                        A03L012
 (12 events)
                                     Alarms - I05W001                                   from: 2018-07-25       to: 2018-07-25
                                                    No Alarms Found for I05W001
                                    Alarms - A05W060                                    from: 2018-07-25       to: 2018-07-25
                                                   No Alarms Found for A05W060
                                    Alarms - A05W061                                    from: 2018-07-25       to: 2018-07-25
                                                   No Alarms Found for A05W061
                                    Alarms - A05W062                                    from: 2018-07-25       to: 2018-07-25
                                                   No Alarms Found for A05W062
                      Alarm events - Alarm events. Last 25 Events:                      from: 2018-07-25       to: 2018-07-25
 Event Name                                      Date GMT+2:00            Source                Destination             Risk
 AlienVault HIDS: SSH insecure connection
                                                2018-07-25 23:55:07    192.168.116.11             I05L002
 attempt (scan).
 AlienVault HIDS: SSH insecure connection
                                                2018-07-25 23:50:05    192.168.116.11             I05L002
 attempt (scan).
 AlienVault HIDS: SSH insecure connection
                                                2018-07-25 23:45:11    192.168.116.11             I05L002
 attempt (scan).
 AlienVault HIDS: SSH insecure connection
                                                2018-07-25 23:40:06    192.168.116.11             I05L002
 attempt (scan).
 AlienVault HIDS: SSH insecure connection
                                                2018-07-25 23:35:10    192.168.116.11             I05L002
 attempt (scan).
User: admin / 2018-07-26 07:18:36                                                                                      Page 3 / 7
                                                                                                           Daily reports Postilion
 AlienVault HIDS: SSH insecure connection
                                                       2018-07-25 23:30:20            192.168.116.11                I05L002
 attempt (scan).
 AlienVault HIDS: SSH insecure connection
                                                       2018-07-25 23:25:19            192.168.116.11                I05L002
 attempt (scan).
 AlienVault HIDS: SSH insecure connection
                                                       2018-07-25 23:20:15            192.168.116.11                I05L002
 attempt (scan).
 AlienVault HIDS: SSH insecure connection
                                                       2018-07-25 23:15:03            192.168.116.11                I05L002
 attempt (scan).
 AlienVault HIDS: SSH insecure connection
                                                       2018-07-25 23:10:08            192.168.116.11                I05L002
 attempt (scan).
 AlienVault HIDS: SSH insecure connection
                                                       2018-07-25 23:05:06            192.168.116.11                I05L002
 attempt (scan).
 AlienVault HIDS: SSH insecure connection
                                                       2018-07-25 23:00:10            192.168.116.11                I05L002
 attempt (scan).
 AlienVault HIDS: SSH insecure connection
                                                       2018-07-25 22:55:07            192.168.116.11                I05L002
 attempt (scan).
 directive_event: AV Bruteforce attack, login
                                                       2018-07-25 22:53:34              A00W195                      0.0.0.0
 authentication attack against 192.168.179.10
 directive_event: AV Bruteforce attack, login
                                                       2018-07-25 22:53:34              A00W195                    A03L012:49
 authentication attack against 192.168.179.10
 AlienVault HIDS: SSH insecure connection
                                                       2018-07-25 22:50:11            192.168.116.11                I05L002
 attempt (scan).
 AlienVault HIDS: SSH insecure connection
                                                       2018-07-25 22:45:05            192.168.116.11                I05L002
 attempt (scan).
 AlienVault HIDS: SSH insecure connection
                                                       2018-07-25 22:39:59            192.168.116.11                I05L002
 attempt (scan).
 directive_event: AV Bruteforce attack, login
                                                       2018-07-25 22:37:05              A05W069                      0.0.0.0
 authentication attack against 10.20.20.17
 AlienVault HIDS: SSH insecure connection
                                                       2018-07-25 22:35:04            192.168.116.11                I05L002
 attempt (scan).
 AlienVault HIDS: SSH insecure connection
                                                       2018-07-25 22:30:06            192.168.116.11                I05L002
 attempt (scan).
 AlienVault HIDS: SSH insecure connection
                                                       2018-07-25 22:25:06            192.168.116.11                I05L002
 attempt (scan).
 AlienVault HIDS: SSH insecure connection
                                                       2018-07-25 22:20:13            192.168.116.11                I05L002
 attempt (scan).
 AlienVault HIDS: SSH insecure connection
                                                       2018-07-25 22:14:57            192.168.116.11                I05L002
 attempt (scan).
 AlienVault HIDS: SSH insecure connection
                                                       2018-07-25 22:10:07            192.168.116.11                I05L002
 attempt (scan).
                                 Logins - Logins. Last 25 Events:                                       from: 2018-07-25        to: 2018-07-25
   Date
                 Event Name                Device IP                Username                  Source                    Dest.
   GMT+2:00
                 AlienVault HIDS:
    2018-07-25
                 Successful login during        192.168.157.10                 swmu                A00W195:59665                A07L006
     23:59:58
                 non-business hours.
User: admin / 2018-07-26 07:18:36                                                                                                         Page 4 / 7
                                                                                        Daily reports Postilion
                AlienVault HIDS:
   2018-07-25
                Successful login during      192.168.179.10           SYSTEM     A00W195               A00W195
    23:59:57
                non-business hours.
                AlienVault HIDS:
   2018-07-25
                Successful login during      192.168.179.10           SYSTEM     A00W195               A00W195
    23:59:57
                non-business hours.
                AlienVault HIDS: Special
   2018-07-25
                privileges assigned to new   192.168.179.10           SYSTEM     A00W195               A00W195
    23:59:57
                logon
                AlienVault HIDS: Special
   2018-07-25
                privileges assigned to new   192.168.179.10           SYSTEM     A00W195               A00W195
    23:59:57
                logon
                AlienVault HIDS:
   2018-07-25
                Windows Network Logon        192.168.179.10           A00W125$    0.0.0.0              A00W195
    23:59:57
                AlienVault HIDS:
   2018-07-25
                Windows Network Logon        192.168.179.10           A00W125$    0.0.0.0              A00W195
    23:59:57
                AlienVault HIDS:
   2018-07-25
                Windows Network Logon        192.168.179.10           A00W125$    0.0.0.0              A00W195
    23:59:57
                AlienVault HIDS:
   2018-07-25
                Windows Network Logon        192.168.179.10           A00W125$    0.0.0.0              A00W195
    23:59:57
                AlienVault HIDS:
   2018-07-25
                Windows Network Logon        192.168.179.10           A00W125$    0.0.0.0              A00W195
    23:59:57
                AlienVault HIDS:
   2018-07-25
                Windows Network Logon        192.168.179.10           A00W125$    0.0.0.0              A00W195
    23:59:57
                AlienVault HIDS:
   2018-07-25
                Successful login during      197.97.220.130     SQLSERVERAGENT   I05W001               I05W001
    23:59:56
                non-business hours.
                AlienVault HIDS:
   2018-07-25
                Successful login during      197.97.220.130     SQLSERVERAGENT   I05W001               I05W001
    23:59:56
                non-business hours.
                AlienVault HIDS:
   2018-07-25
                Successful login during      197.97.220.130     SQLSERVERAGENT   I05W001               I05W001
    23:59:56
                non-business hours.
                AlienVault HIDS:
   2018-07-25
                Successful login during      197.97.220.130     SQLSERVERAGENT   I05W001               I05W001
    23:59:56
                non-business hours.
                AlienVault HIDS:
   2018-07-25
                Successful login during      197.97.220.130     SQLSERVERAGENT   I05W001               I05W001
    23:59:56
                non-business hours.
                AlienVault HIDS:
   2018-07-25
                Successful login during      197.97.220.130     SQLSERVERAGENT   I05W001               I05W001
    23:59:56
                non-business hours.
                AlienVault HIDS:
   2018-07-25
                Successful login during      197.97.220.130     SQLSERVERAGENT   I05W001               I05W001
    23:59:56
                non-business hours.
                AlienVault HIDS:
   2018-07-25
                Successful login during      197.97.220.130     SQLSERVERAGENT   I05W001               I05W001
    23:59:56
                non-business hours.
                AlienVault HIDS:
   2018-07-25
                Successful login during      197.97.220.130     SQLSERVERAGENT   I05W001               I05W001
    23:59:56
                non-business hours.
                AlienVault HIDS:
   2018-07-25
                Successful login during      197.97.220.130     SQLSERVERAGENT   I05W001               I05W001
    23:59:56
                non-business hours.
                AlienVault HIDS:
   2018-07-25
                Successful login during      197.97.220.130     SQLSERVERAGENT   I05W001               I05W001
    23:59:56
                non-business hours.
                AlienVault HIDS:
   2018-07-25
                Successful login during      197.97.220.130     SQLSERVERAGENT   I05W001               I05W001
    23:59:56
                non-business hours.
                AlienVault HIDS:
   2018-07-25
                Successful login during      197.97.220.130     SQLSERVERAGENT   I05W001               I05W001
    23:59:56
                non-business hours.
                AlienVault HIDS:
   2018-07-25
                Successful login during      197.97.220.130     SQLSERVERAGENT   I05W001               I05W001
    23:59:56
                non-business hours.
                             Cleartext - Cleartext. Last 25 Events:                 from: 2018-07-25   to: 2018-07-25
 No data available
User: admin / 2018-07-26 07:18:36                                                                                Page 5 / 7
                                                                                   Daily reports Postilion
              FTP Failed Logons - FTP Failed Logons. Last 25 Events:             from: 2018-07-25      to: 2018-07-25
 No data available
     PCI - Protect Stored Data - Database Succesful Logins. Last 25 Events:      from: 2018-07-25      to: 2018-07-25
 Event Name                                Date GMT+2:00               Source            Destination            Risk
 AlienVault HIDS: MS SQL Server Logon
                                          2018-07-25 18:00:55          I05W001             I05W001
 Success.
 AlienVault HIDS: MS SQL Server Logon
                                          2018-07-25 18:00:55          I05W001             I05W001
 Success.
 AlienVault HIDS: MS SQL Server Logon
                                          2018-07-25 18:00:55          I05W001             I05W001
 Success.
 AlienVault HIDS: MS SQL Server Logon
                                          2018-07-25 18:00:55          I05W001             I05W001
 Success.
 AlienVault HIDS: MS SQL Server Logon
                                          2018-07-25 18:00:51          I05W001             I05W001
 Success.
 AlienVault HIDS: MS SQL Server Logon
                                          2018-07-25 18:00:51          I05W001             I05W001
 Success.
 AlienVault HIDS: MS SQL Server Logon
                                          2018-07-25 18:00:51          I05W001             I05W001
 Success.
 AlienVault HIDS: MS SQL Server Logon
                                          2018-07-25 18:00:51          I05W001             I05W001
 Success.
 AlienVault HIDS: MS SQL Server Logon
                                          2018-07-25 18:00:51          I05W001             I05W001
 Success.
 AlienVault HIDS: MS SQL Server Logon
                                          2018-07-25 18:00:51          I05W001             I05W001
 Success.
 AlienVault HIDS: MS SQL Server Logon
                                          2018-07-25 18:00:51          I05W001             I05W001
 Success.
 AlienVault HIDS: MS SQL Server Logon
                                          2018-07-25 18:00:51          I05W001             I05W001
 Success.
 AlienVault HIDS: MS SQL Server Logon
                                          2018-07-25 18:00:51          I05W001             I05W001
 Success.
 AlienVault HIDS: MS SQL Server Logon
                                          2018-07-25 18:00:51          I05W001             I05W001
 Success.
 AlienVault HIDS: MS SQL Server Logon
                                          2018-07-25 18:00:51          I05W001             I05W001
 Success.
 AlienVault HIDS: MS SQL Server Logon
                                          2018-07-25 18:00:51          I05W001             I05W001
 Success.
 AlienVault HIDS: MS SQL Server Logon
                                          2018-07-25 18:00:51          I05W001             I05W001
 Success.
 AlienVault HIDS: MS SQL Server Logon
                                          2018-07-25 18:00:51          I05W001             I05W001
 Success.
 AlienVault HIDS: MS SQL Server Logon
                                          2018-07-25 18:00:51          I05W001             I05W001
 Success.
 AlienVault HIDS: MS SQL Server Logon
                                          2018-07-25 18:00:51          I05W001             I05W001
 Success.
User: admin / 2018-07-26 07:18:36                                                                              Page 6 / 7
                                                                             Daily reports Postilion
 AlienVault HIDS: MS SQL Server Logon
                                        2018-07-25 18:00:25      I05W001             I05W001
 Success.
 AlienVault HIDS: MS SQL Server Logon
                                        2018-07-25 18:00:25      I05W001             I05W001
 Success.
 AlienVault HIDS: MS SQL Server Logon
                                        2018-07-25 18:00:25      I05W001             I05W001
 Success.
 AlienVault HIDS: MS SQL Server Logon
                                        2018-07-25 18:00:25      I05W001             I05W001
 Success.
 AlienVault HIDS: MS SQL Server Logon
                                        2018-07-25 18:00:21      I05W001             I05W001
 Success.
        Custom Security Events - Windows User Logons. Last 25 Events:      from: 2018-07-25    to: 2018-07-25
 No data available
User: admin / 2018-07-26 07:18:36                                                                      Page 7 / 7