FICSIT-FW-EDGE-01  ·  Pioneer Division — Edge Perimeter
Active
Threat DB v8841
--:-- UTC
8
Reports Available
3
Critical Findings
Require attention
2
Warnings
3
Clean
Today
Last Generated
2026-05-28 14:00 UTC
Daily
Schedule
+ Weekly / Monthly
Daily Reports Auto-generated · 2026-05-28
Threat Intelligence Summary
RPT-2026-0528-001 Generated: 2026-05-28 14:00 UTC Period: 2026-05-28 00:00 → 14:00 UTC Daily
Final 3 Critical

Three critical threat events were detected during the reporting window. A confirmed command-and-control beacon (IPS-5821) from internal host 10.42.3.88 (PIONEER-WS-01) to known C2 infrastructure at 185.220.101.47 was blocked and flagged for investigation. A supply-chain IOC match (IPS-5817) was intercepted during lateral SMB transfer, and a 47 Gbps volumetric DDoS (IPS-5814) was mitigated via upstream null-route. Active security response is ongoing for the C2 and supply-chain events.

3
Critical
4
High
3
Medium
5
Blocked
547 MB
Suspected Exfil
3
SIEM Linked
Top Threat Events
IDSeverityCategoryNameActionSIEM Ref
IPS-5821CriticalC2Beacon to Known C2 Infrastructureblock-ipALT-7287
IPS-5817CriticalMalwareSupply Chain IOC — Malicious Binary in Transitblock-ipALT-7155
IPS-5814CriticalDoSVolumetric DDoS — SYN Flood — 47 Gbpsblock-ipALT-7188
IPS-5819HighExploitSQL Injection — UNION-Based Blind Extractionreset-bothALT-7181
IPS-5816HighBrute ForceVPN Auth Brute Force — 8,420 attemptsblock-ipALT-7231
Traffic Analytics Report
RPT-2026-0528-002 Generated: 2026-05-28 14:00 UTC Period: Last 24 hours Daily
Final 1 Warning

Total firewall throughput during the 24-hour window peaked at 47 Gbps inbound during the 14:00 DDoS event — well above the 7 Gbps baseline. Outbound traffic spiked to 5.8 Gbps at 15:00 UTC, coinciding with the suspected data exfiltration window. Normal egress baseline is 3.5 Gbps. SSL and web-browsing remain the dominant application categories. The SCADA zone correctly blocked 2 unauthorized internet-bound DNS queries from 10.42.250.20.

47.0
Peak In (Gbps)
5.8
Peak Out (Gbps)
75
Log Entries
41
Allowed
28
Denied
6
Dropped
Top Applications by Sessions
ApplicationCategorySessionsRisk
dnsnetworking91,200low
sslnetworking48,291medium
web-browsinggeneral-internet31,044low
office365business-systems22,819low
industrial-protocolics-scada1,100high
IPS Event Summary
RPT-2026-0528-003 Generated: 2026-05-28 14:00 UTC Period: Last 24 hours Daily
Final Active Incident

The IPS engine processed 15 signature matches across the reporting window, generating 3 critical, 5 high, and 4 medium severity events. Active incident: PIONEER-WS-01 (10.42.3.88) continues to generate C2 beacon attempts at 2-minute intervals targeting 185.220.101.47. All attempts are blocked at the edge. The supply-chain binary transfer (IPS-5817) has been escalated to the incident response team. SQL injection campaign from 203.0.113.88 against the DMZ web tier has subsided following IP block.

15
Total Events
3
Critical
5
High
4
Medium
12
Auto-Blocked
8
IPs Blocked
Events by Category
CategoryCountAuto-Blocked
C2 / Exfiltration21
Exploit (SQLi / XSS)33
Malware22
Brute Force11
DoS / DDoS11
Reconnaissance22
Policy Violation32
ICS / OT Anomaly10
VPN Session Summary
RPT-2026-0528-004 Generated: 2026-05-28 14:00 UTC Period: Last 24 hours Daily
Final Brute Force Attempt

VPN gateway processed 18,440 inbound tunnel negotiations during the reporting window. A brute-force credential stuffing attack from 91.134.77.22 (8,420 attempts) was detected and blocked at 10:30 UTC — the source IP has been added to the threat intelligence block list. Three legitimate VPN client sessions (172.16.100.x) remain active with normal activity patterns. No unauthorized authentications were recorded.

18,440
Auth Attempts
3
Active Sessions
8,420
Blocked (Brute)
12,844
Current Sessions
Active VPN Clients
Client IPAssigned IPStatusConnected
external client172.16.100.44active14:59 UTC
external client172.16.100.88active14:05 UTC
external client172.16.100.33active09:33 UTC
91.134.77.22blocked10:30 UTC (8,420 attempts)
Weekly Reports Auto-generated · Week of 2026-05-25
Executive Security Summary
RPT-2026-W21-001 Generated: 2026-05-28 00:00 UTC Period: 2026-05-21 → 2026-05-28 Weekly
Final Active Incident

The week of 2026-05-21 saw an elevated threat posture for the Pioneer Division perimeter. An active security incident is underway: workstation PIONEER-WS-01 is exhibiting persistent C2 beacon behavior to threat actor infrastructure, with a concurrent supply-chain IOC detection on the same host. A 47 Gbps DDoS event was successfully mitigated without service disruption. SQL injection attacks against the DMZ web tier were blocked and the source IP was null-routed. All 14 security policies remain active and correctly enforced. No unauthorized network access has been confirmed.

1
Active Incident
15
IPS Events (7d)
14
Policies Active
99.98%
Uptime
0
Confirmed Breaches
Recommended Actions
Isolate PIONEER-WS-01 (10.42.3.88) pending forensic investigation — active C2 and supply-chain IOC match.
Escalate ALT-7287 and ALT-7155 to incident response. Determine extent of lateral movement from 10.42.7.14 → 10.42.3.88.
Review DMZ web server (10.42.200.10) application logs for any successful SQL injection payload execution following IPS-5819.
Update credential hygiene for VPN users following brute-force campaign targeting this gateway.
SCADA zone isolation is functioning correctly — unauthorized internet access attempts were blocked. No action required.
Security Policy Audit
RPT-2026-W21-002 Generated: 2026-05-28 00:00 UTC Period: 2026-05-21 → 2026-05-28 Weekly
Final All Policies Active

All 14 security policies are enabled and actively matching traffic. No orphaned, shadowed, or unused rules were detected during the weekly audit. The default-deny baseline policy (Rule 14) recorded 1,092,847 hits — consistent with normal internet-facing noise. The highest-traffic allow rule is Rule 8 (Allow-Internal-Web-Outbound) with 2.8M+ hits. OT isolation policies (Rules 3, 11) are performing correctly.

14
Total Policies
14
Active
0
Unused Rules
0
Shadowed Rules
Top Rules by Hit Count
#Rule NameActionHit Count
8Allow-Internal-Web-Outboundallow2,847,103
14Deny-All-Inbound-Defaultdeny1,092,847
6Allow-DMZ-Web-Inboundallow889,244
1Block-TI-Malicious-Hostsdeny14,872
5Allow-VPN-to-Internalallow62,310
Monthly Reports Auto-generated · May 2026
Top Blocked Sources — Monthly
RPT-2026-M05-001 Generated: 2026-05-01 00:00 UTC Period: May 2026 Monthly
Final Nominal

The top blocked external source IPs for May 2026 are consistent with known scanning and opportunistic attack infrastructure. The most frequently blocked IP is 185.220.101.47 — a Tor exit node and known C2 host — which has generated 14,872 block hits this month. Port scanning from commercial reconnaissance services (Shodan-affiliated ranges) accounts for approximately 22% of all blocked inbound traffic.

Top 6 Blocked Source IPs
Source IPZoneBlock HitsPrimary ReasonCategory
185.220.101.47External14,872TI Block List — C2 InfrastructureCritical
45.142.212.100External9,441Port Scan / VPN Brute ForceHigh
91.134.77.22External8,420VPN Credential StuffingHigh
203.0.113.88External6,110SQL Injection CampaignHigh
198.51.100.77External3,291Tor Exit NodeMedium
203.0.113.201External2,188ICMP / Host SweepLow
Compliance Status Report
RPT-2026-M05-002 Generated: 2026-05-01 00:00 UTC Period: May 2026 Monthly
Final 1 Finding

The Pioneer Division perimeter firewall is in general compliance with ICS/OT segmentation requirements. The SCADA zone has zero direct internet connectivity and all cross-zone flows from OT to IT are restricted to the approved historian path. One compliance finding: log forwarding is disabled on Rule 8 (Allow-Internal-Web-Outbound), which reduces visibility into high-volume outbound sessions. Recommend enabling log forwarding for this rule with a sampling rate to balance storage costs.

12
Controls Pass
1
Finding
0
Critical Gaps
Yes
OT Isolation
Control Assessment
ControlStatusNotes
OT/SCADA network isolationPassRule 3 enforced — 0 outbound internet sessions
Default-deny inbound policyPassRule 14 — 1.09M hits blocked this month
Threat intelligence integrationPassFeed updated every 15 min — 14,872 blocks
Remote access authenticationPassIPsec/SSL VPN — MFA enforced
Log forwarding coverageFindingRule 8 log forwarding disabled — reduce visibility gap
Zone protection profilesPassAll 6 zones have active protection profiles