Investigate
Console route · /infrastructure-map
Infrastructure Map
Geographic view of company endpoints and observed malicious contact paths. Legacy /threat-globe and /threat-graph redirect here. This is not the internal NDR topology page.
What the globe shows
The map places company endpoints from tenant inventory and draws arcs for correlated remote contacts that meet evidence rules. Filters cover time, minimum risk, country, and evidence feed. Playback walks connection timelines. Inspectors expose endpoint and connection detail. Sync and polling refresh when live.
How inventory gets onto the map
Admin can import endpoint inventory (hostname, IP, geo) used for correlation. Evaluation mode synthesizes endpoints from demo assets for walkthroughs. Geographic proximity alone never creates a path — a remote indicator must be correlated with tenant evidence within the product’s correlation rules.
Boundaries
Realtime WebSocket fanout may be handshake-only in some deployments; the UI remains idle without published telemetry rather than inventing motion. For internal east-west topology and lateral movement graphs, use NDR (/investigation). Legacy routes /threat-globe and /infra-map redirect here permanently.