Daily Activity Report

Friday, Mar 20, 2026 (through 3:19 AM)

Generated Mar 20, 2026 3:28 AM

0
Active Users
0
User Sessions
0
RDP Sessions
7
Failed Logons
0
Print Jobs
0
USB Events
1
Screenshots
80
Sysmon Events
26
Network Clients

Data Source Warnings

Today at a Glance (AI Summary)

Generated by Gemini Flash

User Activity (Domain Authentication)

No domain logons recorded for this period.

Remote Desktop Sessions (Guacamole / RDP)

No RDS sessions recorded for this period.

Failed Logon Attempts

UserFailuresSource
hani@mdmcontracting.ca7HANY-PC

Top Applications (Server)

No application data for this period.

DNS Top Sites

ClientDomainQueries
Reception-2-PCarray612.prod.do.dsp.mp.microsoft.com2
ATEF-PCcanadaeast1-0.pushnp.svc.ms4
Localself.events.data.microsoft.com8
Localgraph.microsoft.com11
MDM-Servercqd.teams.cloud.microsoft2
Hany-PCdefault.exp-tas.com2
MDM-Serverwww.microsoft.com2
MDM-Serverregistry.npmjs.org2
Reception-2-PCclient.wns.windows.com19
MDM-Serverecs.nel.measure.office.net10
EHAB-PCarray603.prod.do.dsp.mp.microsoft.com4
ATEF-PCv10.events.data.microsoft.com15
ATEF-PCecs.office.com4
192.168.128.19ca-prod.asyncgw.teams.microsoft.com2
192.168.128.195p69hiii4m.execute-api.us-east-1.amazonaws.com7
MDM-Server1076-ms-7.9733-16762b84.1c44b9df-20ae-11f1-8f9d-2cea7f579a3a1
Localca-prod.asyncgw.teams.microsoft.com12
192.168.128.24cfd-features.argotunnel.com5
MDM-Serverimg-s-msn-com.akamaized.net2
Hany-PCclients4.google.com12

Workstation Activity (Agent)

MDM-SERVER (Administrator) — 1 snapshots, avg idle: 29s

Top Window TitlesCount
⠂ soul-production-guardrails1
Top ProcessesSeen
cmd2
mmc1
WebPlugin_NVR1
msedge1
ServerManager1
BrowserDomainVisitsSample Page
Edgego.microsoft.com1Dashboard - Microsoft Teams admin center
Edgelogin.microsoft.com6Redirecting
Edgeservicetrust.microsoft.com3Service Trust Portal Home Page
Edgen93.dashboard.meraki.com12Organization settings - Meraki Dashboard
Edgelogin.microsoftonline.com27Sign in to your account
Edge08f1b3661a1f.devices.meraki.direct:8092408f1b3661a1f.devices.meraki.direct:8092/index.html#connec...
Edgeteams.cloud.microsoft15MDM Claw | MDM Claw | Microsoft Teams
Edgeaccount.meraki.com4Meraki Dashboard Login
Edgeadmin.teams.microsoft.com17Microsoft Teams admin center - Microsoft Teams admin center
Edgebing.com4cisco meraki dashboard - Search

Endpoint Deep Visibility (Sysmon)

Per-process command lines, network connections, and DNS from Sysmon on endpoints. 80 total events across 1 endpoint(s).

Administrator

ProcessDestinationPortCount
dns.exeATEF-PC501411
dns.exe192.168.128.24335851
claude.exe137.66.149.34.bc.googleusercontent.com4431
dns.exeATEF-PC529731
dns.exeATEF-PC645071
dns.exedns.google531
dns.exe192.168.2.72637001
RustDesk.exe100.72.136.17211161
dns.exe192.168.128.24465801
SystemEHAB-PC1371
dns.exe192.168.128.8509191
dns.exe192.168.2.72516991
dns.exe192.168.2.72533901
dns.exe192.168.128.24336601
dns.exe192.168.2.72521251
ProcessCommand LineParentCount
bash.exe"C:\Program Files\Git\bin\..\usr\bin\bash.exe" -c "python3 /c/Users/Administrator/.claude/plugins/cache/claude-plugin...bash.exe1
wsmprovhost.exeC:\Windows\system32\wsmprovhost.exe -Embeddingsvchost.exe1
bash.exe"C:\Program Files\Git\bin\bash.exe" -c "python3 /c/Users/Administrator/.claude/plugins/cache/claude-plugins-official/...claude.exe1
bash.exe"C:\Program Files\Git\bin\..\usr\bin\bash.exe" -c "python3 /c/Users/Administrator/.claude/plugins/cache/claude-plugin...bash.exe1
cvtres.exeC:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\ADMINI~1\Ap...csc.exe1
dllhost.exeC:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}svchost.exe1
bash.exe"C:\Program Files\Git\bin\..\usr\bin\bash.exe" -c "python3 /c/Users/Administrator/.claude/plugins/cache/claude-plugin...bash.exe1
bash.exe"C:\Program Files\Git\bin\bash.exe" -c "python3 /c/Users/Administrator/.claude/plugins/cache/claude-plugins-official/...claude.exe1
bash.exe"C:\Program Files\Git\bin\bash.exe" -c "python3 /c/Users/Administrator/.claude/plugins/cache/claude-plugins-official/...claude.exe1
bash.exe"C:\Program Files\Git\bin\bash.exe" -c "python3 /c/Users/Administrator/.claude/plugins/cache/claude-plugins-official/...claude.exe1
ProcessDomainCount
lsass.exe_ldap._tcp.Default-First-Site-Name._sites.DomainDnsZones.MDM.local1
lsass.exe_ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.MDM.local1
claude.exehttp-intake.logs.us5.datadoghq.com1
lsass.exe_ldap._tcp.b2acf55b-0c55-43f8-8ad3-cd9c960643e2.domains._msdcs.MDM.local1
lsass.exe_kerberos._tcp.Default-First-Site-Name._sites.MDM.local1
lsass.exegc._msdcs.MDM.local1
lsass.exe_ldap._tcp.Default-First-Site-Name._sites.ForestDnsZones.MDM.local1
lsass.exeForestDnsZones.MDM.local1
lsass.exe_ldap._tcp.Default-First-Site-Name._sites.gc._msdcs.MDM.local1
lsass.exe_gc._tcp.Default-First-Site-Name._sites.MDM.local1

Network Traffic (Meraki)

ClientIPSent (MB)Received (MB)Total (MB)
e49caeaf-cd07-4dee-b1c1-53b6febc88b3192.168.2.2260.10.60.8
2ca4ad96-36dc-4e02-a907-3ef735a7db7f192.168.2.1970.300.3
Dalia-Salib-PC192.168.2.1530.32.32.6
DMs-iPhone192.168.2.1830.15.96
BB8836102192.168.2.73000
Nervine-PC192.168.2.720.10.40.5
f2:f6:44:fc:d6:43192.168.2.128000
18J180104009192.168.2.187000
46:0a:10:11:6a:78192.168.2.111000
f69b87fb-29a5-4800-becc-978641060148192.168.2.1270.10.70.8
14:2f:fd:0d:d3:0d192.168.2.64000
c0:74:ad:1b:b1:db192.168.2.94000
BB8836154192.168.2.124000
Watch192.168.2.98000
iPhone192.168.2.2170.20.20.5

Microsoft 365 Activity

Email & Teams data is from Mar 19 (yesterday — Microsoft reports have a ~24h processing delay). Sign-ins are real-time.

Sign-In Activity

UserAppLocationStatusLast Time
Michael GuirguisApp Studio for Microsoft TeamsMississauga, CAFailed (65002)Mar 20 12:36 AM
Michael GuirguisMicrosoft Graph Command Line ToolsMississauga, CAFailed (50199)Mar 20 12:24 AM
Michael GuirguisMicrosoft Teams Web ClientMississauga, CASuccessMar 20 12:43 AM
Michael GuirguisNetBirdMississauga, CASuccessMar 20 12:14 AM
Michael GuirguisApp Studio for Microsoft TeamsMississauga, CASuccessMar 20 12:36 AM
Michael GuirguisMicrosoft Teams Admin Portal ServiceMississauga, CASuccess (4x)Mar 20 1:13 AM
Michael GuirguisAzure PortalMississauga, CASuccessMar 20 12:36 AM
Michael GuirguisBot Framework Dev PortalMississauga, CASuccessMar 20 12:37 AM
Michael GuirguisOffice365 Shell WCSS-ClientMississauga, CASuccess (6x)Mar 20 12:53 AM
Hani AbdelmalekOne Outlook WebMississauga, CASuccessMar 20 2:29 AM
Michael GuirguisMicrosoft Graph Command Line ToolsMississauga, CASuccessMar 20 12:27 AM

File Access (Shared Drives)

No file access events recorded. Data will appear once users access audited shares.