The Detections Panel is the core investigative hub within the Lumu Portal. When suspicious activity on your network escalates into a confirmed incident, this panel serves as your team's starting point for rapid triage and response. It is designed to transform complex, raw metadata into a clear and actionable narrative, providing analysts with the exact context they need to understand the scope, severity, and source of an attack.
Because no two cyber threats operate exactly the same way, the Detections Panel is built to be highly dynamic. Rather than forcing a static dashboard on every alert, the interface adapts its layout and the data it presents based on the specific incident type detected.
For example, for a
DNS Tunneling incident will display the following information:

While a
Login Brute Force incident will display the following:

Regardless of the threat, the Detections Panel ensures that the most critical, incident-specific intelligence is always front and center, empowering your security operations team to make faster, more accurate decisions during an active investigation.
Lumu Incident Detections
Check out the following articles to fully understand the information shown in the Lumu Portal by each incident detection:
- Log Tamperging Detection
- DNS Tunneling Detection
- Login Brute Force Detection
- Unusual Login Detection
- Data Exfiltration Detection
- Anonymized Login Detection
- Network Brute Force Detection