Case 01
Autonomous Hunter
20 IPs. Zero Alerts. Invisible Brute Force.
Autonomous Hunter uncovered a distributed brute force campaign across 20+ international IPs using the OrgIdWsTrust2 legacy auth endpoint — completely invisible to Microsoft SigninLogs, MFA, and Conditional Access. Standard SIEM rules are blind to this vector.
20+
Attacker IPs across 8+ countries
0
Alerts generated in SIEM
33
Failed logons via legacy endpoint
100%
Detection gap in SigninLogs
Legacy authentication endpoints are active blind spots in every SIEM. Without behavioral anomaly detection, these attacks run indefinitely — undetected.
Case 02
Alert Refinery
One of the World's Largest MDRs was Overrun.
Alert Refinery labeled the queue first, scoring every alert statistically and clearing duplicates and known-benign patterns with auditable evidence, no detector changes required.
17.9B
Events across customer telemetry
375,000+
Incidents generated in one month
1,000+
Analysts and engineers on staff
56.9%
Incidents cleared as duplicate or benign
They'd already tried a full AI SOC platform, couldn't run at their scale, and it never made it past the first eval.
Case 03
Autonomous Hunter
DCsync Attack. Uninvestigated for 35 Days.
Two DCsync alerts (MITRE ATT&CK T1003.006) sat in the SIEM with status "New" for over a month — unread, uninvestigated. Autonomous Hunter correlated 4 identity events across 48 hours and reconstructed the full Kerberos kill chain, delivering a verdict in minutes.
35
Days alerts sat uninvestigated
4
Events correlated across 48 hrs
4,273+
Normal vs. 2 anomalous events
Minutes
To verdict vs. analyst hours
Detection without investigation is just noise. Autonomous Hunter builds the case in minutes — not just an alert, a verdict.
Case 04
Autonomous Hunter
Server 2008 R2. 255 Citrix Users. Zero Monitoring.
Autonomous Hunter discovered a Windows Server 2008 R2 (end-of-life since January 2020) serving 255 Citrix users daily with zero telemetry. Found through behavioral network analysis alone — no agent required. Zero patches since 2020.
2009
OS release year (EOL Jan 2020)
255
Daily Citrix users exposed
0
Patches applied since EOL
Every environment has servers that fell through the cracks. Autonomous Hunter surfaces them before an attacker finds them first.
Case 05
Autonomous Hunter
110 MB Over Telnet. Median is 17 KB.
Two telnet sessions transferring 100+ MB each to a legacy on-premises device — 6,000x the normal median — off-hours, by a near-ghost user with only 2 total logons ever. No endpoint agent. No Azure presence. Invisible to every traditional tool.
17 KB
Normal median per session
110 MB
Detected transfer (6,000x median)
2
Ghost user's total logons ever
0
Traditional tools could see this
No one knew what this device was, who was using it, or why 200 MB moved over telnet off-hours. Required immediate investigation.
Case 06
Autonomous Hunter
700 Cleartext LDAP Binds. 6 Accounts Exposed.
A management server was authenticating to all 11 domain controllers via cleartext LDAP (port 389) — transmitting 6 service account passwords unencrypted ~700 times per day. No signature existed for this volume. Zero alerts generated.
700
Cleartext binds per day
6
High-privilege accounts exposed
11
Domain controllers at risk
A single packet capture on the network segment would have compromised the entire infrastructure stack. Migrate to LDAPS immediately.
Case 07
Autonomous Hunter
3,625 KMS Calls. One Admin Role.
A 50x spike in KMS Decrypt calls — Z-score of 573 — traced to 59 Lambda functions running with full administrative privileges. A developer elevated for testing and never reverted. Indistinguishable from post-compromise credential exfiltration.
6–160
Normal KMS calls per day
3,625
Calls in 2 hours (Z-score: 573)
59
Lambda functions as AdminRole
375
Severity score (top in env)
Running production Lambda functions as admin is identical to what an attacker does after privilege escalation. Concrete remediation target delivered with full context.