Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 14:40:04 UTC

Port Scan Detected

Medium False Positive
ALR-00005 · 2026-05-21T18:48:57Z

Description

Sequential port scan (1-1024) detected targeting SRV-BACKUP-01 from external IP. EmilyAI Triage identified SYN scan pattern.

Alert Metadata

Alert ID
ALR-00005
Timestamp
2026-05-21T18:48:57Z
Severity
Medium
Status
False Positive
Detection Source
EmilyAI Triage
Assigned Analyst
Sarah Chen

Endpoint Information

Hostname
SRV-BACKUP-01
User Account
l.johnson
Source IP
185.220.220.176
Destination IP
10.2.175.72
Origin Country
CN China

MITRE ATT&CK Mapping

Tactic
Reconnaissance
Technique
T1046
Reference
attack.mitre.org/techniques/T1046

Investigation Timeline

18:48:57 Event ingested by SOC365 Engine
18:48:59 EmilyAI triage started — correlation enrichment
18:49:07 EmilyAI confidence: 78% — escalated to human analyst
18:49:25 Alert assigned to analyst: Sarah Chen
18:51:47 Investigation started — querying SIEM and threat intelligence
18:52:39 Containment action taken — endpoint isolated
19:02:30 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00192 2h ago Rogue DHCP Server Low Resolved SRV-BACKUP-01
ALR-00293 13h ago Port Scan Detected Informational Resolved WS-MAC-005
ALR-00392 15h ago Pass-the-Hash Detected Medium Investigating SRV-BACKUP-01
ALR-00476 17h ago Port Scan Detected Medium Escalated WS-PC-003
ALR-00038 1d ago Port Scan Detected High Open WS-PC-001