Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 14:41:16 UTC

Port Scan Detected

Medium Escalated
ALR-00009 · 2026-05-24T07:15:11Z

Description

Sequential port scan (1-1024) detected targeting WS-MAC-005 from external IP. Firewall identified SYN scan pattern.

Alert Metadata

Alert ID
ALR-00009
Timestamp
2026-05-24T07:15:11Z
Severity
Medium
Status
Escalated
Detection Source
Firewall
Assigned Analyst
Marcus Webb

Endpoint Information

Hostname
WS-MAC-005
User Account
d.walker
Source IP
185.47.220.217
Destination IP
10.1.234.121
Origin Country
FR France

MITRE ATT&CK Mapping

Tactic
Reconnaissance
Technique
T1046
Reference
attack.mitre.org/techniques/T1046

Investigation Timeline

07:15:11 Event ingested by SOC365 Engine
07:15:16 EmilyAI triage started — correlation enrichment
07:15:23 EmilyAI confidence: 96% — escalated to human analyst
07:15:44 Alert assigned to analyst: Marcus Webb
07:16:17 Investigation started — querying SIEM and threat intelligence
07:25:03 Containment action taken — endpoint isolated
07:28:23 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00285 6h ago Privilege Escalation Attempt Informational Escalated WS-MAC-005
ALR-00381 7h ago Port Scan Detected Informational Escalated WS-PC-006
ALR-00181 7h ago Data Exfiltration Attempt Low False Positive WS-MAC-005
ALR-00375 9h ago Brute Force SSH Low Investigating WS-MAC-005
ALR-00157 11h ago Port Scan Detected Informational False Positive SRV-DC-01