Anomalous DNS Query
Low
Escalated
ALR-00138 · 2026-04-09T22:01:42Z
Description
DNS query to known DGA-generated domain from WS-LAP-011. EmilyAI Triage matched pattern against threat intelligence feed. User: j.smith.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
22:01:42
Event ingested by SOC365 Engine
22:01:46
EmilyAI triage started — correlation enrichment
22:01:57
EmilyAI confidence: 82% — escalated to human analyst
22:02:07
Alert assigned to analyst: EmilyAI (auto)
22:03:10
Investigation started — querying SIEM and threat intelligence
22:11:40
Containment action taken — endpoint isolated
22:17:39
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00035 | 59m ago | Kerberoasting Attempt | Low | Escalated | WS-LAP-011 |
| ALR-00192 | 10h ago | Anomalous DNS Query | Low | Resolved | WS-PC-006 |
| ALR-00245 | 14h ago | Lateral Movement Detected | Low | Escalated | WS-LAP-011 |
| ALR-00353 | 19h ago | Anomalous DNS Query | Low | Open | SRV-DC-01 |
| ALR-00385 | 20h ago | Phishing Email Blocked | Low | Escalated | WS-LAP-011 |