Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 13:55:03 UTC

C2 Beacon Activity

Informational Resolved
ALR-00034 · 2026-04-11T03:14:46Z

Description

Suspected C2 beacon detected from WS-LAP-012. Regular 60-second interval HTTPS POST to suspicious domain. Cloud Connector blocked outbound.

Alert Metadata

Alert ID
ALR-00034
Timestamp
2026-04-11T03:14:46Z
Severity
Informational
Status
Resolved
Detection Source
Cloud Connector
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
WS-LAP-012
User Account
s.jones
Source IP
185.54.220.151
Destination IP
10.0.100.6
Origin Country
IR Iran

MITRE ATT&CK Mapping

Tactic
Command and Control
Technique
T1071.001
Reference
attack.mitre.org/techniques/T1071.001

Investigation Timeline

03:14:46 Event ingested by SOC365 Engine
03:14:47 EmilyAI triage started — correlation enrichment
03:14:53 EmilyAI confidence: 85% — escalated to human analyst
03:15:25 Alert assigned to analyst: EmilyAI (auto)
03:16:07 Investigation started — querying SIEM and threat intelligence
03:23:20 Containment action taken — endpoint isolated
03:28:33 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00463 2h ago Suspicious Scheduled Task High Investigating WS-LAP-012
ALR-00484 4h ago Unauthorised USB Device Informational Escalated WS-LAP-012
ALR-00070 4h ago C2 Beacon Activity Medium False Positive WS-PC-002
ALR-00206 5h ago Unusual Outbound Traffic Informational False Positive WS-LAP-012
ALR-00018 6h ago Certificate Anomaly Informational Resolved WS-LAP-012