Benign log event
Noise (matching type)
Attack event
⚠ Couldn't load the 3D engineThree.js failed to load from the CDN. Check your connection and reload.
Security Information and Event Management platforms don't detect attacks by magic — they run correlation rules over a firehose of log events. This simulator renders the most common rule type, a sliding-window count threshold, in real 3D: six hosts stream ordinary background noise and occasional brute-force bursts toward a central correlation engine, and an alert only fires once enough matching events land inside the current time window for the same host. Tune the window length, the event threshold, and the background noise rate to see the true-positive/false-positive tradeoff every SOC analyst tunes in production, then inject a brute-force attack and watch the mean-time-to-detect play out live.