Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 13:52:48 UTC

Anomalous DNS Query

Low Resolved
ALR-00046 · 2026-04-06T23:47:07Z

Description

DNS query to known DGA-generated domain from SW-CORE-01. SOC365 Engine matched pattern against threat intelligence feed. User: j.smith.

Alert Metadata

Alert ID
ALR-00046
Timestamp
2026-04-06T23:47:07Z
Severity
Low
Status
Resolved
Detection Source
SOC365 Engine
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
SW-CORE-01
User Account
j.smith
Source IP
45.118.148.252
Destination IP
10.2.223.223
Origin Country
NL Netherlands

MITRE ATT&CK Mapping

Tactic
Command and Control
Technique
T1568.002
Reference
attack.mitre.org/techniques/T1568.002

Investigation Timeline

23:47:07 Event ingested by SOC365 Engine
23:47:08 EmilyAI triage started — correlation enrichment
23:47:17 EmilyAI confidence: 91% — escalated to human analyst
23:47:29 Alert assigned to analyst: EmilyAI (auto)
23:48:29 Investigation started — querying SIEM and threat intelligence
23:56:24 Containment action taken — endpoint isolated
23:59:39 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00079 54m ago Anomalous DNS Query Medium Resolved AP-WIFI-03
ALR-00067 58m ago Anomalous DNS Query Low Escalated WS-LAP-011
ALR-00288 5h ago Anomalous DNS Query Medium Escalated FW-EDGE-01
ALR-00481 5h ago Failed MFA Challenge High Investigating SW-CORE-01
ALR-00321 9h ago Anomalous DNS Query Medium Open WS-LAP-012