Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 15:53:50 UTC

Certificate Anomaly

Informational False Positive
ALR-00069 · 2026-05-21T16:05:37Z

Description

TLS certificate anomaly detected on WS-LAP-012. Self-signed certificate on port 443 does not match expected corporate CA chain.

Alert Metadata

Alert ID
ALR-00069
Timestamp
2026-05-21T16:05:37Z
Severity
Informational
Status
False Positive
Detection Source
DLP Module
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
WS-LAP-012
User Account
r.davies
Source IP
103.204.216.35
Destination IP
10.0.210.232
Origin Country
KP North Korea

MITRE ATT&CK Mapping

Tactic
Defence Evasion
Technique
T1553.004
Reference
attack.mitre.org/techniques/T1553.004

Investigation Timeline

16:05:37 Event ingested by SOC365 Engine
16:05:38 EmilyAI triage started — correlation enrichment
16:05:51 EmilyAI confidence: 84% — escalated to human analyst
16:06:02 Alert assigned to analyst: EmilyAI (auto)
16:06:23 Investigation started — querying SIEM and threat intelligence
16:11:30 Containment action taken — endpoint isolated
16:24:02 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00202 3h ago Certificate Anomaly Low Open WS-PC-002
ALR-00223 5h ago Certificate Anomaly Low Escalated SRV-BACKUP-01
ALR-00241 7h ago Rogue DHCP Server Medium False Positive WS-LAP-012
ALR-00199 10h ago Certificate Anomaly Medium Escalated SRV-APP-01
ALR-00348 11h ago Pass-the-Hash Detected Low False Positive WS-LAP-012