Home»Time Entries Audit loading ... [hide int notes] generated 8/8/2026 at 9:39:34 pm took 0.82 seconds version: b85cbb8 helpers: v2

Territory: BMS Month: « Apr 2026 » Company: CT [x] Ticket: all User: all Type: Remote [x] Role: all Bill: all Timesheet: all  3/30 4/6 4/13 4/20 4/27 Board: all Entry Status: all Ticket Status: all Issue: all [reset] Progress: 0% (0 of 1)

row id Terr Company User Date Day Start End Actual Billed Deduct Inv Amt Work Type Work Role Bill Timesheet Board Entry Status Ticket Status Ticket # Ticket Summary Int Notes Audit Done Audit Notes Notes # issues all issues errors warnings notices
1 38988 BMS CT fdrewett 4/20 7:00 am 8:00 am 1.00 1.00 0 125.00 Remote Standard Technician Billable 4/20 Help Desk 2.1 Billed -Closed 74499 Huntress ITDR Incident #2093168 — Critical — Courageous Transformations 0 Huntress ITDR Incident #2093168 — Critical — Courageous Transformations Incident: https://bms.huntress.io/org/295830/infection\_reports/2093168 Summary: Huntress detected a successful suspicious authentication to M365 account charlotteb@couragenm.com on 2026-04-20 12:51:16 UTC from 47.253.180.189 \(Alibaba Cloud - US, Virginia\) using user agent axios/1.15.0 against the OfficeHome application. Device was non-compliant/unmanaged. Axios UA is associated with Phishing-as-a-Service kits and automated credential validation / session hijacking. Huntress auto-revoked sessions and disabled the identity. IOCs: - User: charlotteb@couragenm.com - Src IP: 47.253.180.189 \(Alibaba Cloud - US\) - User Agent: axios/1.15.0 - Session ID: 00401e2a-2a11-ede3-62cf-26b1d4d97c1e - App: OfficeHome \(4765445b-32c6-49b0-83e6-1d93765276ca\) - Device: Non-compliant, Unmanaged Remediation actions completed: 1\. Contained account in M365 admin center — reset password to a new strong value, blocked sign-in, and initiated sign-out to revoke all refresh tokens\. 2\. Verified per-user MFA status: Enforced\. 3\. Audited registered MFA / authentication methods in Entra for charlotteb — no unfamiliar phone numbers, Authenticator registrations, or alternate emails\. No attacker-registered methods present\. 4\. Reviewed Entra sign-in logs for the user — no additional suspicious successful sign-ins identified beyond the Huntress-flagged event; no 'Previously satisfied' MFA from foreign IPs observed\. 1 Notices: Notes: Notes longer than 500 characters Notes: Notes longer than 500 characters

Legend:
(hover over fields for details)

Error (0)
Warning (0)
Notice (1)


Notices

Field Message Count
Notes  Notes longer than 500 characters  1
Total  1


38988 - fdrewett - 4/20 7:00 am - 74499 - Huntress ITDR Incident #2093168 — Critical — Courageous Transformations
Notes longer than 500 characters