Protocol SIFT Sentinel

Autonomous evidence correlation for incident response
GitHub

Primary Hypothesis

Coordinated web compromise with credential pressure.

The agent initially treated brute force as isolated. After correlation, it promoted the case because web, DNS, and EDR events formed a consistent attacker timeline.

Evidence Timeline

AUTH-00100:10:11ZSSH failed password for app-admin
AUTH-00600:11:02ZSSH success from same source ASN
WEB-00200:13:44ZPHP upload to public web root
EDR-00100:14:05Zphp-fpm starts /bin/sh
DNS-00100:14:08ZNewly observed beacon domain queried
Contain
Isolate web-01 and block outbound beaconing.
Preserve
Capture auth logs, web root, process telemetry, and hashes.
Recover
Rotate app-admin credentials and invalidate sessions.
Hunt
Search adjacent hosts for the same domain and PHP process pattern.