Autonomous Hunter

108K DNS Queries. 1,129 Pass-the-Ticket Alerts.

1,129
pass-the-ticket alerts, cleared in a single automated pass
~108K
DNS anomaly, queries/week from 8-node forwarder
1,129
Pass-the-ticket alerts, Kerberos tickets used from VPN IPs
0
Malicious findings, both confirmed false positives
0
Analyst hours, both resolved in a single automated pass

The problem

Two alarming signals, traced to normal infrastructure, resolved without a single analyst touch.

Two alarming signals correlated and traced to normal infrastructure — a DNS spike from an 8-node forwarder cluster and 1,129 Kerberos PtT alerts from VPN users. Both resolved without a single analyst touch.

Alert Correlation

Two separate anomalies — a DNS surge and 1,129 Kerberos PtT alerts — were investigated together. The Autonomous Hunter connected them to the same infrastructure pattern, triaging both in a single pass instead of two separate multi-hour investigations.

False Positive Elimination

1,129 PtT alerts would bury a SOC team for days. The Autonomous Hunter identified the VPN/Kerberos delegation pattern instantly — a known false positive that most teams learn to silently ignore or build manual exclusion rules for. We proved it automatically.

Infrastructure Awareness

The system mapped the 8-node DNS forwarder cluster, identified the remote domain and cross-forest trust relationships — the kind of environmental context that takes human analysts weeks to develop and is rarely documented anywhere.

The lesson

Neither detection was malicious. But without investigation, 1,129 PtT alerts and 108K DNS queries would have consumed hundreds of analyst hours — or been silently ignored.

Contact us for a 30-day POV
on your own identity infrastructure.

Book a Demo
Or reach us directly at hello@alphalevelsec.com  ·  alphalevel.ai