Observations

← Dashboard Detections ATT&CK
Observations are adversary captures from your deception surface. Each observation is a learning artifact — raw tradecraft you can turn into detection rules and test against your SOC's real-world readiness. External observations (Nythrix-hosted decoys) sample internet-scale tradecraft; internal observations (decoys inside your environment) are confirmed in-env intrusions and trigger urgent IR. Every observation ships with a composite risk score (0-100) that now factors your detection coverage for the observed techniques. View raw detections →
Risk Pillar OODA Canary Source IP Severity Retriggers Last Seen Status
Loading...