Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 13:55:06 UTC

Ransomware Behaviour Detected

Medium Escalated
ALR-00023 · 2026-04-08T03:33:33Z

Description

File encryption behaviour detected on VM-DEV-01. 142 files renamed with .locked extension in 30 seconds. Attack Surface Scanner isolated endpoint.

Alert Metadata

Alert ID
ALR-00023
Timestamp
2026-04-08T03:33:33Z
Severity
Medium
Status
Escalated
Detection Source
Attack Surface Scanner
Assigned Analyst
Emma Richardson

Endpoint Information

Hostname
VM-DEV-01
User Account
s.jones
Source IP
91.245.195.87
Destination IP
10.0.99.229
Origin Country
CN China

MITRE ATT&CK Mapping

Tactic
Impact
Technique
T1486
Reference
attack.mitre.org/techniques/T1486

Investigation Timeline

03:33:33 Event ingested by SOC365 Engine
03:33:34 EmilyAI triage started — correlation enrichment
03:33:44 EmilyAI confidence: 78% — escalated to human analyst
03:33:58 Alert assigned to analyst: Emma Richardson
03:36:16 Investigation started — querying SIEM and threat intelligence
03:37:31 Containment action taken — endpoint isolated
03:49:26 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00386 13h ago Ransomware Behaviour Detected Low False Positive VM-DEV-01
ALR-00029 13h ago Shadow IT Discovery Informational Resolved VM-DEV-01
ALR-00448 17h ago Suspicious PowerShell Execution Medium Open VM-DEV-01
ALR-00039 21h ago DLP Policy Violation Low Resolved VM-DEV-01
ALR-00352 1d ago Ransomware Behaviour Detected Informational Resolved WS-LAP-012