What an alert actually looks like.
Every detection ships as a forensic bundle, not a one-liner. Click between the tabs below to see the email body, the evidence we attach, the parsed IOCs, and the raw network transcript.
Hello — we detected a confirmed malicious injection on a page you monitor.
Target: https://shop.yourcompany.com/checkout
Detection time: 14:01:09 UTC (delay: 98s after injection)
Classification: Drive-by iframe → SocGholish payload
The page loaded a hidden iframe pointing at cdn-helper-stats[.]xyz/loader.js which executed a known SocGholish dropper. The injection appears to originate from a compromised version of the "quick-cart" WordPress plugin.
Full evidence bundle (screenshot, HAR, replay URL, IOC list) is attached and viewable in your dashboard. Recommended action: roll back plugin to v3.1.4 and rotate any admin credentials touched in the last 72h.
— Domain Exploits Detector // automated alert