Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 15:54:12 UTC

Tor Exit Node Connection

Medium Open
ALR-00084 · 2026-05-22T17:05:16Z

Description

Connection from SRV-SQL-01 to known Tor exit node detected by SOC365 Engine. User 'd.walker' was active at the time.

Alert Metadata

Alert ID
ALR-00084
Timestamp
2026-05-22T17:05:16Z
Severity
Medium
Status
Open
Detection Source
SOC365 Engine
Assigned Analyst
Anika Patel

Endpoint Information

Hostname
SRV-SQL-01
User Account
d.walker
Source IP
185.166.220.228
Destination IP
10.2.17.205
Origin Country
KP North Korea

MITRE ATT&CK Mapping

Tactic
Command and Control
Technique
T1090.003
Reference
attack.mitre.org/techniques/T1090.003

Investigation Timeline

17:05:16 Event ingested by SOC365 Engine
17:05:21 EmilyAI triage started — correlation enrichment
17:05:23 EmilyAI confidence: 83% — escalated to human analyst
17:05:56 Alert assigned to analyst: Anika Patel
17:06:34 Investigation started — querying SIEM and threat intelligence

Related Alerts

ID Time Alert Severity Status Host
ALR-00474 6h ago Privilege Escalation Attempt Low Open SRV-SQL-01
ALR-00032 11h ago Tor Exit Node Connection Informational Resolved VM-DEV-01
ALR-00363 14h ago Privilege Escalation Attempt Low Open SRV-SQL-01
ALR-00097 22h ago Tor Exit Node Connection Medium Investigating WS-PC-003
ALR-00244 1d ago Unusual Outbound Traffic Medium False Positive SRV-SQL-01