Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 13:55:54 UTC

Certificate Anomaly

Informational Resolved
ALR-00018 · 2026-04-12T07:15:43Z

Description

TLS certificate anomaly detected on WS-LAP-012. Self-signed certificate on port 443 does not match expected corporate CA chain.

Alert Metadata

Alert ID
ALR-00018
Timestamp
2026-04-12T07:15:43Z
Severity
Informational
Status
Resolved
Detection Source
SOC365 Engine
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
WS-LAP-012
User Account
system
Source IP
91.253.195.249
Destination IP
10.0.200.145
Origin Country
US United States

MITRE ATT&CK Mapping

Tactic
Defence Evasion
Technique
T1553.004
Reference
attack.mitre.org/techniques/T1553.004

Investigation Timeline

07:15:43 Event ingested by SOC365 Engine
07:15:47 EmilyAI triage started — correlation enrichment
07:15:50 EmilyAI confidence: 86% — escalated to human analyst
07:15:58 Alert assigned to analyst: EmilyAI (auto)
07:17:58 Investigation started — querying SIEM and threat intelligence
07:22:17 Containment action taken — endpoint isolated
07:28:38 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00463 2h ago Suspicious Scheduled Task High Investigating WS-LAP-012
ALR-00484 4h ago Unauthorised USB Device Informational Escalated WS-LAP-012
ALR-00206 5h ago Unusual Outbound Traffic Informational False Positive WS-LAP-012
ALR-00394 8h ago Brute Force SSH Medium False Positive WS-LAP-012
ALR-00095 10h ago Insider Threat Indicator Low Open WS-LAP-012