Posture: Watch ◌ loading live data… Riverside Action Network · 6 sources · 790K+ events Investigations →
Distant Early Warning · Security Intelligence
◆ WATCH

What's watching us — and what we're watching for.

DEWLine brings six common security channels — your logins, website, devices, and email — into one place, and reasons over all of it at once, in plain English. Refreshes at midnight and noon daily.

Privacy by default — every name and personal detail is automatically changed; the real identities appear only to cleared staff signed into the live tool.

4
Critical users flagged by two independent systems
confirm — don't conclude
0
Attacker paths from web/endpoint into login
cross-checked, clean
602
Messages spoofing our domain
DMARC quarantined them
7
Detections running across the store
d001–d007
01

Combined Threat Report

Everything the systems agree on, ranked by what deserves attention first. Prompts for confirmation, not verdicts.

Two systems independently flag the same four accounts

j.okafor, t.nguyen, d.reyes, and a.morgan are each flagged by both Coro (endpoint) and Google Workspace login rules. Independent tools agreeing is the strongest signal we have.

Priority

j.okafor@ — three endpoint identity-compromise alerts + a Mexico login

Coro flagged suspected identity compromise three times; Workspace shows a login from a Mexican ISP. Not proof — a conversation: is Mexico access expected?

Investigate

admin@ signing in through a Panama VPN

Part of a wider pattern of staff on commercial VPNs. An administrator account being anonymized is the one worth confirming first.

Confirm

Our own mail may be failing authentication

A service on AWS sent 768 messages as our domain that failed DMARC — likely a real vendor of ours, misconfigured. Legitimate mail could be hitting spam.

Fix

The perimeter is holding

Cloudflare and WordPress are blocking brute-force and bots; no blocked IP ever reached a login; domain spoofers are quarantined. The defenses are working.

Clear
◆

Threat Context Index

Each flagged account gets a 0–100 score with the reasons behind it, in plain language — a higher score just means it deserves a closer look. Green reasons calm the score; red ones raise it. It ranks where to look; people decide what to do.

◌ loading the index…
02

Report by Channel

Each system is one sense. Alone, each sees a slice; together they see the whole.

Google Workspace Watch
Identity — who signed in, from where
717K
events
525
failed logins
3
suspicious
Google itself flagged 3 logins as suspicious. No brute-force succeeded — but several critical users sign in through VPNs.
Cloudflare Clear
Web edge — traffic to our website
25K
events / 3d
2,378
blocked
20K
challenged
The edge absorbs the noise — thousands of bots challenged or blocked before reaching the site. Retention is only ~3 days.
WordPress Clear
Website — logins & admin activity
4.5K
events
482
blocked
133
banned IPs
Brute-force on the login page is locked out. None of the banned attackers reached the identity layer.
Coro Attention
Endpoints — critical users' devices
5
identity-compromise
2
impossible travel
2
mass download
Watching only critical accounts — so every alert matters. j.okafor (×3), m.silva, and t.nguyen were flagged for identity compromise.
DMARC Watch
Email authentication — mail sent as us
20K
records
235K
clean msgs
602
failed
Spoofers forging our domain are quarantined — but a legitimate vendor's mail is failing too, a deliverability fix worth making.
Email Quarantine Watch
Quarantined mail — clustered into campaigns
1.7K
quarantined
impers.
flagged
org-wide
now capturing
Most quarantine is our own operational & vendor mail — the real signal underneath is impersonation and auth-failing spoofers, now captured across the whole org, not just watched accounts.
03

Red Team Report

If someone wanted into Riverside Action Network, how would they come? These paths are drawn from patterns already in our data — not hypotheticals.

VECTOR 01

Phish a critical user

Target the ED or senior staff with a convincing login page. Credentials are the front door.

seen: Coro identity-compromise ×5
VECTOR 02

Log in behind a VPN

Use a commercial VPN so the login looks like ordinary remote work, not a foreign IP.

seen: admin@ via Panama VPN
VECTOR 03

Grant a quiet OAuth token

Authorize an app to keep access even after a password reset — persistence without re-login.

watched by: rule d004
VECTOR 04

Impersonate the domain

Spoof riversideaction.org to phish staff, members, and donors — trading on our name.

seen: 602 spoofed messages

⚠ Where we're currently blind

  • Coro watches only critical users — most of the org's endpoints are unmonitored.
  • Cloudflare keeps only ~3 days of history — an older attack is invisible at the edge.
  • Data is pulled manually, so answers can be stale — the platform lowers its own confidence when it is.
  • External threat intelligence and full email-quarantine content aren't wired in yet.
04

Counterstrategy

Each move closes a specific path above. Ordered by leverage — the first two shut the most likely doors for the least effort.

01

Passkeys / phishing-resistant MFA for critical users

A stolen password stops being enough. This alone breaks the phish → VPN-login chain.

closes 01 · 02
02

Fix DMARC alignment, then move to reject

Align legitimate senders, tighten policy from quarantine to reject — real mail lands, spoofers bounce.

closes 04 · deliverability
03

Confirm the flagged accounts

Ask j.okafor about Mexico access and admin@ about the VPN. Two conversations resolve the top of the board.

resolves priority
04

Automate ingestion & extend endpoint coverage

Keep data fresh so answers stay high-confidence, and widen Coro beyond critical users as budget allows.

closes blind spots
05

Report Archive

Every twice-daily assessment, saved for the record. Download the anonymized report, or the official named version when signed in as cleared staff.

◌ loading saved reports…