Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 17:09:15 UTC

Tor Exit Node Connection

Informational False Positive
ALR-00029 · 2026-05-22T06:40:11Z

Description

Connection from WS-MAC-005 to known Tor exit node detected by Cloud Connector. User 'a.wilson' was active at the time.

Alert Metadata

Alert ID
ALR-00029
Timestamp
2026-05-22T06:40:11Z
Severity
Informational
Status
False Positive
Detection Source
Cloud Connector
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
WS-MAC-005
User Account
a.wilson
Source IP
91.166.195.174
Destination IP
10.3.129.39
Origin Country
IR Iran

MITRE ATT&CK Mapping

Tactic
Command and Control
Technique
T1090.003
Reference
attack.mitre.org/techniques/T1090.003

Investigation Timeline

06:40:11 Event ingested by SOC365 Engine
06:40:13 EmilyAI triage started — correlation enrichment
06:40:19 EmilyAI confidence: 94% — escalated to human analyst
06:40:34 Alert assigned to analyst: EmilyAI (auto)
06:41:05 Investigation started — querying SIEM and threat intelligence
06:49:54 Containment action taken — endpoint isolated
06:53:21 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00253 6h ago Port Scan Detected Low Open WS-MAC-005
ALR-00409 15h ago DecoyPulse Honeypot Triggered Medium Investigating WS-MAC-005
ALR-00174 15h ago Tor Exit Node Connection Informational Resolved WS-PC-004
ALR-00088 1d ago Credential Stuffing Attempt Low Investigating WS-MAC-005
ALR-00330 1d ago Brute Force SSH Medium Investigating WS-MAC-005