Anomalous DNS Query
Medium
Escalated
ALR-00057 · 2026-05-24T09:55:26Z
Description
DNS query to known DGA-generated domain from SRV-SQL-01. Endpoint Agent matched pattern against threat intelligence feed. User: d.walker.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
09:55:26
Event ingested by SOC365 Engine
09:55:31
EmilyAI triage started — correlation enrichment
09:55:36
EmilyAI confidence: 91% — escalated to human analyst
09:55:55
Alert assigned to analyst: Anika Patel
09:56:30
Investigation started — querying SIEM and threat intelligence
10:01:51
Containment action taken — endpoint isolated
10:12:05
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00279 | 49m ago | Privilege Escalation Attempt | Informational | Escalated | SRV-SQL-01 |
| ALR-00024 | 3h ago | Phishing Email Blocked | Low | Investigating | SRV-SQL-01 |
| ALR-00188 | 5h ago | Credential Stuffing Attempt | Low | Escalated | SRV-SQL-01 |
| ALR-00465 | 10h ago | Brute Force SSH | Informational | Resolved | SRV-SQL-01 |
| ALR-00173 | 16h ago | C2 Beacon Activity | Medium | Investigating | SRV-SQL-01 |