Triage a network alert where one source hits one exposed service with repeated logins or exploit payloads — internet-reachable remote admin (SSH, RDP, SMB), brute force against exposed logins, and CVE or exploit attempts on edge appliances. Reads flow records and firewall logs for the source identity, the attempt pattern, and whether any auth succeeded to tell a sanctioned admin apart from access that actually got through, and decides escalate or dismiss.