Combined Threat Report
Everything the systems agree on, ranked by what deserves attention first. Prompts for confirmation, not verdicts.
Two systems independently flag the same four accounts
j.okafor, t.nguyen, d.reyes, and a.morgan are each flagged by both Coro (endpoint) and Google Workspace login rules. Independent tools agreeing is the strongest signal we have.
j.okafor@ — three endpoint identity-compromise alerts + a Mexico login
Coro flagged suspected identity compromise three times; Workspace shows a login from a Mexican ISP. Not proof — a conversation: is Mexico access expected?
admin@ signing in through a Panama VPN
Part of a wider pattern of staff on commercial VPNs. An administrator account being anonymized is the one worth confirming first.
Our own mail may be failing authentication
A service on AWS sent 768 messages as our domain that failed DMARC — likely a real vendor of ours, misconfigured. Legitimate mail could be hitting spam.
The perimeter is holding
Cloudflare and WordPress are blocking brute-force and bots; no blocked IP ever reached a login; domain spoofers are quarantined. The defenses are working.
Threat Context Index
Each flagged account gets a 0–100 score with the reasons behind it, in plain language — a higher score just means it deserves a closer look. Green reasons calm the score; red ones raise it. It ranks where to look; people decide what to do.
Report by Channel
Each system is one sense. Alone, each sees a slice; together they see the whole.
Red Team Report
If someone wanted into Riverside Action Network, how would they come? These paths are drawn from patterns already in our data — not hypotheticals.
Phish a critical user
Target the ED or senior staff with a convincing login page. Credentials are the front door.
seen: Coro identity-compromise ×5Log in behind a VPN
Use a commercial VPN so the login looks like ordinary remote work, not a foreign IP.
seen: admin@ via Panama VPNGrant a quiet OAuth token
Authorize an app to keep access even after a password reset — persistence without re-login.
watched by: rule d004Impersonate the domain
Spoof riversideaction.org to phish staff, members, and donors — trading on our name.
seen: 602 spoofed messages⚠ Where we're currently blind
- Coro watches only critical users — most of the org's endpoints are unmonitored.
- Cloudflare keeps only ~3 days of history — an older attack is invisible at the edge.
- Data is pulled manually, so answers can be stale — the platform lowers its own confidence when it is.
- External threat intelligence and full email-quarantine content aren't wired in yet.
Counterstrategy
Each move closes a specific path above. Ordered by leverage — the first two shut the most likely doors for the least effort.
Passkeys / phishing-resistant MFA for critical users
A stolen password stops being enough. This alone breaks the phish → VPN-login chain.
Fix DMARC alignment, then move to reject
Align legitimate senders, tighten policy from quarantine to reject — real mail lands, spoofers bounce.
Confirm the flagged accounts
Ask j.okafor about Mexico access and admin@ about the VPN. Two conversations resolve the top of the board.
Automate ingestion & extend endpoint coverage
Keep data fresh so answers stay high-confidence, and widen Coro beyond critical users as budget allows.
Report Archive
Every twice-daily assessment, saved for the record. Download the anonymized report, or the official named version when signed in as cleared staff.