Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 18:05:21 UTC

C2 Beacon Activity

Informational Investigating
ALR-00101 · 2026-05-22T18:24:39Z

Description

Suspected C2 beacon detected from SRV-MAIL-01. Regular 60-second interval HTTPS POST to suspicious domain. Cloud Connector blocked outbound.

Alert Metadata

Alert ID
ALR-00101
Timestamp
2026-05-22T18:24:39Z
Severity
Informational
Status
Investigating
Detection Source
Cloud Connector
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
SRV-MAIL-01
User Account
m.taylor
Source IP
45.29.148.179
Destination IP
10.0.245.23
Origin Country
RU Russia

MITRE ATT&CK Mapping

Tactic
Command and Control
Technique
T1071.001
Reference
attack.mitre.org/techniques/T1071.001

Investigation Timeline

18:24:39 Event ingested by SOC365 Engine
18:24:44 EmilyAI triage started — correlation enrichment
18:24:50 EmilyAI confidence: 83% — escalated to human analyst
18:25:04 Alert assigned to analyst: EmilyAI (auto)
18:27:11 Investigation started — querying SIEM and threat intelligence

Related Alerts

ID Time Alert Severity Status Host
ALR-00002 9h ago Anomalous DNS Query Informational False Positive SRV-MAIL-01
ALR-00134 20h ago Privilege Escalation Attempt Medium Escalated SRV-MAIL-01
ALR-00300 1d ago C2 Beacon Activity Informational False Positive WS-MAC-005
ALR-00378 1d ago Ransomware Behaviour Detected Medium Escalated SRV-MAIL-01
ALR-00419 1d ago C2 Beacon Activity Medium Escalated SRV-BACKUP-01