Detection Settings
Adjust sliders to tune detection sensitivity — findings recompute live.
Trigger 'high failed count' finding when a single user exceeds this many failures.
Trigger a finding when a single source IP exceeds this many failures.
How many distinct accounts one IP must target inside the window.
Time window in minutes for spray detection.
Spray is 'low-volume, wide' — cap attempts per user to distinguish from brute-force.
Failures against one user within the window to fire brute-force.
Time window for brute-force detection.
Minimum implied travel speed to flag as impossible.
Ignore hops shorter than this — reduces noise from ISP hopping.
Ignore back-to-back sign-ins closer than this.
Start of the 'off-hours' window used for off-hours findings and the timeline heatmap.
End of the off-hours window.
Silence before a sign-in counts as a dormant account reactivation.
How long a source IP must be silent before a burst is interesting.
Events within one hour after the quiet period to fire the finding.
Off-hours detection and the timeline heatmap use this offset instead of your browser timezone, so the same log file always produces the same findings.
Muted rules still run but their findings are suppressed.
Settings are stored in your browser's localStorage. Findings are recomputed automatically when values change.
