Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 13:53:37 UTC

Port Scan Detected

Informational Resolved
ALR-00075 · 2026-04-06T00:19:53Z

Description

Sequential port scan (1-1024) detected targeting WS-PC-004 from external IP. Cloud Connector identified SYN scan pattern.

Alert Metadata

Alert ID
ALR-00075
Timestamp
2026-04-06T00:19:53Z
Severity
Informational
Status
Resolved
Detection Source
Cloud Connector
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
WS-PC-004
User Account
n.clark
Source IP
91.214.195.66
Destination IP
10.2.85.108
Origin Country
NL Netherlands

MITRE ATT&CK Mapping

Tactic
Reconnaissance
Technique
T1046
Reference
attack.mitre.org/techniques/T1046

Investigation Timeline

00:19:53 Event ingested by SOC365 Engine
00:19:55 EmilyAI triage started — correlation enrichment
00:20:00 EmilyAI confidence: 93% — escalated to human analyst
00:20:17 Alert assigned to analyst: EmilyAI (auto)
00:21:52 Investigation started — querying SIEM and threat intelligence
00:27:23 Containment action taken — endpoint isolated
00:37:37 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00384 22m ago Port Scan Detected Informational Open SRV-APP-01
ALR-00391 2h ago Port Scan Detected Low False Positive SRV-BACKUP-01
ALR-00255 2h ago Brute Force SSH Medium False Positive WS-PC-004
ALR-00227 2h ago Port Scan Detected High Open WS-PC-002
ALR-00249 4h ago Certificate Anomaly Low Resolved WS-PC-004