| P1 | Falco rule triggered: shell in DB pod | Cloudflare | open | soc-l2 | 5/4/2026, 4:10:30 AM |
| P2 | Falco rule triggered: shell in DB pod | Wazuh | acknowledged | unassigned | 5/4/2026, 3:25:30 AM |
| P0 | Canarytoken triggered: wallet_events | OpenBao | resolved | unassigned | 5/4/2026, 2:40:30 AM |
| P2 | Falco rule triggered: shell in DB pod | Falco | open | unassigned | 5/4/2026, 1:55:30 AM |
| P2 | Falco rule triggered: shell in DB pod | OpenBao | resolved | oncall | 5/4/2026, 1:10:30 AM |
| P2 | Falco rule triggered: shell in DB pod | OpenBao | open | unassigned | 5/4/2026, 12:25:30 AM |
| P2 | Unusual pg_dump outside maintenance window | Sentry | open | soc-l1 | 5/3/2026, 11:40:30 PM |
| P1 | Suspicious SQLi pattern on /api/v3/wallet | Suricata | resolved | oncall | 5/3/2026, 10:55:30 PM |
| P0 | Anomalous login spike from unknown ASN | OpenBao | resolved | unassigned | 5/3/2026, 10:10:30 PM |
| P2 | Falco rule triggered: shell in DB pod | Cloudflare | open | soc-l1 | 5/3/2026, 9:25:30 PM |