Rogue DHCP Server
Low
Investigating
ALR-00038 · 2026-04-08T09:18:45Z
Description
Rogue DHCP server detected on VLAN 10 from SW-CORE-01. Offering IPs in unexpected range. Endpoint Agent quarantined the device.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
09:18:45
Event ingested by SOC365 Engine
09:18:47
EmilyAI triage started — correlation enrichment
09:18:56
EmilyAI confidence: 80% — escalated to human analyst
09:19:26
Alert assigned to analyst: EmilyAI (auto)
09:20:58
Investigation started — querying SIEM and threat intelligence
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00427 | 19m ago | Port Scan Detected | Informational | Open | SW-CORE-01 |
| ALR-00113 | 1h ago | Credential Stuffing Attempt | Informational | False Positive | SW-CORE-01 |
| ALR-00205 | 8h ago | Anomalous DNS Query | Medium | Investigating | SW-CORE-01 |
| ALR-00381 | 10h ago | Phishing Email Blocked | Critical | Investigating | SW-CORE-01 |
| ALR-00214 | 19h ago | Rogue DHCP Server | Low | Resolved | SRV-DC-01 |