Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 13:50:45 UTC

Ransomware Behaviour Detected

Informational False Positive
ALR-00131 · 2026-04-09T07:53:06Z

Description

File encryption behaviour detected on SRV-FILE-01. 142 files renamed with .locked extension in 30 seconds. Attack Surface Scanner isolated endpoint.

Alert Metadata

Alert ID
ALR-00131
Timestamp
2026-04-09T07:53:06Z
Severity
Informational
Status
False Positive
Detection Source
Attack Surface Scanner
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
SRV-FILE-01
User Account
j.smith
Source IP
194.116.62.7
Destination IP
10.3.80.142
Origin Country
US United States

MITRE ATT&CK Mapping

Tactic
Impact
Technique
T1486
Reference
attack.mitre.org/techniques/T1486

Investigation Timeline

07:53:06 Event ingested by SOC365 Engine
07:53:07 EmilyAI triage started — correlation enrichment
07:53:13 EmilyAI confidence: 83% — escalated to human analyst
07:53:27 Alert assigned to analyst: EmilyAI (auto)
07:55:30 Investigation started — querying SIEM and threat intelligence
07:56:39 Containment action taken — endpoint isolated
08:12:16 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00382 4h ago Ransomware Behaviour Detected Low Open WS-PC-004
ALR-00148 17h ago Credential Stuffing Attempt Low Investigating SRV-FILE-01
ALR-00043 19h ago Port Scan Detected Medium False Positive SRV-FILE-01
ALR-00111 21h ago Port Scan Detected Informational Resolved SRV-FILE-01
ALR-00164 22h ago Ransomware Behaviour Detected Informational False Positive WS-LAP-010