Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 13:50:29 UTC

Certificate Anomaly

Medium Escalated
ALR-00100 · 2026-04-11T16:41:13Z

Description

TLS certificate anomaly detected on WS-PC-002. Self-signed certificate on port 443 does not match expected corporate CA chain.

Alert Metadata

Alert ID
ALR-00100
Timestamp
2026-04-11T16:41:13Z
Severity
Medium
Status
Escalated
Detection Source
SOC365 Engine
Assigned Analyst
Emma Richardson

Endpoint Information

Hostname
WS-PC-002
User Account
m.taylor
Source IP
91.122.195.103
Destination IP
10.3.46.201
Origin Country
FR France

MITRE ATT&CK Mapping

Tactic
Defence Evasion
Technique
T1553.004
Reference
attack.mitre.org/techniques/T1553.004

Investigation Timeline

16:41:13 Event ingested by SOC365 Engine
16:41:16 EmilyAI triage started — correlation enrichment
16:41:20 EmilyAI confidence: 82% — escalated to human analyst
16:41:42 Alert assigned to analyst: Emma Richardson
16:42:05 Investigation started — querying SIEM and threat intelligence
16:47:12 Containment action taken — endpoint isolated
16:51:25 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00342 14m ago Certificate Anomaly Informational Investigating SRV-DC-01
ALR-00429 1h ago Certificate Anomaly Informational Escalated FW-EDGE-01
ALR-00081 5h ago Certificate Anomaly Medium Open AP-WIFI-03
ALR-00072 16h ago Rogue DHCP Server Informational Open WS-PC-002
ALR-00439 1d ago Certificate Anomaly Critical Escalated WS-PC-006