Endpoint activity monitoring, DLP violations, and device telemetry
| Timestamp | Hostname | User | OS | Event | Details | Status | |
|---|---|---|---|---|---|---|---|
| 2026-03-10 14:35:01 | LAPTOP-JD01 | jdoe | windows | DLP Violation | Detected 3 credit card numbers in clipboard paste to pastebin.com | BLOCKED | |
| 2026-03-10 14:34:40 | LAPTOP-JD01 | jdoe | windows | Clipboard Exfil | Bulk clipboard paste: 2,400 characters copied from internal CRM to external site | BLOCKED | |
| 2026-03-10 14:34:15 | MBP-ALICE | alice | macos | USB Inserted | USB mass storage device "SanDisk Ultra" (32GB) inserted | LOGGED | |
| 2026-03-10 14:33:50 | MBP-ALICE | alice | macos | File → USB | Copied 47 files (128 MB) including customer-database-export.csv to USB drive | BLOCKED | |
| 2026-03-10 14:33:20 | DEV-BOB | bob | linux | Process Start | Process started: /usr/bin/code (Visual Studio Code) PID 4821 | LOGGED | |
| 2026-03-10 14:32:55 | LAPTOP-CHARLIE | charlie | windows | Screen Capture | Screenshot captured while viewing hr.acme.com/payroll — matched DLP rule for sensitive pages | BLOCKED | |
| 2026-03-10 14:32:30 | LAPTOP-CHARLIE | charlie | windows | Print Job | Print job submitted: "Q4-Financial-Report.pdf" (14 pages) to HP LaserJet 4th Floor | LOGGED | |
| 2026-03-10 14:32:05 | WS-EVE | eve | windows | Priv Escalation | Process "cmd.exe" requested elevation to SYSTEM via UAC bypass (fodhelper.exe) | BLOCKED | |
| 2026-03-10 14:31:45 | MBP-DAVE | dave | macos | Network Connect | Outbound connection to 185.244.25.51:4443 (unfamiliar IP, not in known services) | LOGGED | |
| 2026-03-10 14:31:20 | DEV-BOB | bob | linux | Login | SSH login from 10.0.1.42 to dev-bob.internal | LOGGED | |
| 2026-03-10 14:31:00 | WS-EVE | eve | windows | File Encrypt | Rapid file encryption detected: 23 files encrypted in /Documents in 8 seconds — possible ransomware | BLOCKED | |
| 2026-03-10 14:30:40 | LAPTOP-FRANK | frank | windows | Agent Health | ApexAegis agent v2.4.1 healthy — last policy sync 2 minutes ago | LOGGED | |
| 2026-03-10 14:30:15 | MBP-ALICE | alice | macos | DLP Violation | API key (AWS AKIA...) detected in email attachment draft to external recipient | BLOCKED | |
| 2026-03-10 14:30:00 | LAPTOP-JD01 | jdoe | windows | Logout | User session ended — idle timeout 30 minutes | LOGGED |