Analytics

Threat AnalyticsNew

A suite of purpose-built dashboards covering ransomware, malware, lateral movement, credential theft, and impersonation — translating raw security events into actionable threat intelligence.

Threat Analytics

Behavioural threat intelligence dashboards

What it does

Key capabilities

Ransomware Dashboard

Tracks ransomware indicators, encrypted file activity, and suspicious process behaviour across your endpoints.

Malware Dashboard

Aggregates malware detections across all integrated endpoint solutions with trending and per-device drill-down.

Lateral Movement

Detects attacker movement patterns between hosts — privilege escalation, pass-the-hash, and credential reuse.

Credential Theft

Surfaces credential harvesting indicators — LSASS access attempts, suspicious Kerberos activity, and more.

Impersonation Detection

Identifies accounts exhibiting behaviour inconsistent with their normal baseline — a key indicator of account takeover.

Timeline View

Reconstruct attack sequences with an event timeline that maps threat events across your environment chronologically.

Highlights

Why Threat Analytics?

  • Five dedicated dashboards — ransomware, malware, lateral movement, credential theft, impersonation
  • Cross-vendor data correlation across all integrated tools
  • Behavioural baseline per user and device
  • Attack timeline reconstruction
  • Feeds directly into Playbooks for automated response
Included in OneView

Threat Analytics is part of the Hakware OneView platform. All findings, events, and data from this module flow into your central dashboard alongside every other security signal in your environment.

24/7 Support Available
Phone: +27 060 984 1210
FAQs

Frequently asked questions

Threat Analytics provides five purpose-built dashboards: Ransomware (encrypted file activity, suspicious process patterns), Malware (detections across all endpoint vendors), Lateral Movement (pass-the-hash, privilege escalation, credential reuse patterns), Credential Theft (LSASS access attempts, Kerberos anomalies), and Impersonation (account takeover behavioural indicators).

Threat Analytics aggregates normalised event data from all connected security tools — endpoint agents, firewalls, M365, cloud, UBA — and applies correlation logic that spans vendors. A lateral movement indicator might involve a FortiGate event, a Defender alert, and a UBA anomaly together; Threat Analytics surfaces the combined pattern rather than three separate alerts.

The timeline view maps all threat events chronologically across your environment, showing the sequence of attacker actions — initial access, discovery, lateral movement, and impact — as they unfolded. Each event can be clicked to reveal the underlying evidence and source. The timeline can be exported for incident reports and post-mortem reviews.

Specific threat patterns detected in Threat Analytics can trigger automated Playbook executions — for example, a confirmed ransomware indicator on an endpoint can automatically trigger a SentinelOne or Defender quarantine action, an AD account disable, and a notification to the security team, all without analyst intervention.

See Threat Analytics in action

Request a personalised demo and we'll show you exactly how Threat Analytics works within your environment.