Certificate Anomaly
Informational
Investigating
ALR-00059 · 2026-05-26T01:13:43Z
Description
TLS certificate anomaly detected on SRV-SQL-01. Self-signed certificate on port 443 does not match expected corporate CA chain.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
01:13:43
Event ingested by SOC365 Engine
01:13:45
EmilyAI triage started — correlation enrichment
01:13:48
EmilyAI confidence: 83% — escalated to human analyst
01:14:01
Alert assigned to analyst: EmilyAI (auto)
01:14:44
Investigation started — querying SIEM and threat intelligence
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00390 | 6h ago | Certificate Anomaly | Medium | Investigating | WS-PC-003 |
| ALR-00474 | 6h ago | Privilege Escalation Attempt | Low | Open | SRV-SQL-01 |
| ALR-00359 | 8h ago | Certificate Anomaly | Medium | False Positive | WS-PC-006 |
| ALR-00363 | 14h ago | Privilege Escalation Attempt | Low | Open | SRV-SQL-01 |
| ALR-00065 | 1d ago | Certificate Anomaly | Medium | Escalated | AP-WIFI-03 |