Anomalous DNS Query
Low
Resolved
ALR-00046 · 2026-04-06T23:47:07Z
Description
DNS query to known DGA-generated domain from SW-CORE-01. SOC365 Engine matched pattern against threat intelligence feed. User: j.smith.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
23:47:07
Event ingested by SOC365 Engine
23:47:08
EmilyAI triage started — correlation enrichment
23:47:17
EmilyAI confidence: 91% — escalated to human analyst
23:47:29
Alert assigned to analyst: EmilyAI (auto)
23:48:29
Investigation started — querying SIEM and threat intelligence
23:56:24
Containment action taken — endpoint isolated
23:59:39
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00079 | 54m ago | Anomalous DNS Query | Medium | Resolved | AP-WIFI-03 |
| ALR-00067 | 58m ago | Anomalous DNS Query | Low | Escalated | WS-LAP-011 |
| ALR-00288 | 5h ago | Anomalous DNS Query | Medium | Escalated | FW-EDGE-01 |
| ALR-00481 | 5h ago | Failed MFA Challenge | High | Investigating | SW-CORE-01 |
| ALR-00321 | 9h ago | Anomalous DNS Query | Medium | Open | WS-LAP-012 |