Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 18:03:15 UTC

Tor Exit Node Connection

Low Investigating
ALR-00140 · 2026-05-26T19:41:04Z

Description

Connection from WS-PC-004 to known Tor exit node detected by Cloud Connector. User 'a.wilson' was active at the time.

Alert Metadata

Alert ID
ALR-00140
Timestamp
2026-05-26T19:41:04Z
Severity
Low
Status
Investigating
Detection Source
Cloud Connector
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
WS-PC-004
User Account
a.wilson
Source IP
45.183.148.155
Destination IP
10.3.162.11
Origin Country
CN China

MITRE ATT&CK Mapping

Tactic
Command and Control
Technique
T1090.003
Reference
attack.mitre.org/techniques/T1090.003

Investigation Timeline

19:41:04 Event ingested by SOC365 Engine
19:41:09 EmilyAI triage started — correlation enrichment
19:41:17 EmilyAI confidence: 96% — escalated to human analyst
19:41:20 Alert assigned to analyst: EmilyAI (auto)
19:42:10 Investigation started — querying SIEM and threat intelligence

Related Alerts

ID Time Alert Severity Status Host
ALR-00156 12h ago Tor Exit Node Connection Informational Escalated WS-PC-003
ALR-00137 14h ago DecoyPulse Honeypot Triggered Informational False Positive WS-PC-004
ALR-00281 18h ago Shadow IT Discovery Low Investigating WS-PC-004
ALR-00319 19h ago Privilege Escalation Attempt Low Investigating WS-PC-004
ALR-00173 1d ago Port Scan Detected Low False Positive WS-PC-004