The CyberMon dashboard provides a comprehensive view of cybersecurity metrics, including incident
count, activity, notable hosts and users, messages per second, anomaly geo-activity, and case
summaries categorized by MITRE ATT&CK.
Displays the volume and type of network and system activities, helping to identify normal versus suspicious behavior.
Highlights specific hosts that have exhibited significant or unusual activity, indicating potential security concerns or targets for further investigation.
Highlights specific users that have exhibited significant or unusual activity, indicating potential security concerns or targets for further investigation.
Measures the rate at which messages are being processed by the system, providing insights into network load and performance.
Detects and reports on unusual patterns or deviations from normal behavior, indicating potential security threats or breaches.
Maps the geographical locations of network activities, allowing for the visualization of potential threat sources and patterns based on geographic data.
Summarizes cases according to the MITRE ATT&CK framework, categorizing incidents based on known attack techniques and tactics, aiding in understanding and mitigating specific threat vectors.