Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 19:08:16 UTC

Anomalous DNS Query

Low False Positive
ALR-00155 · 2026-05-27T10:15:30Z

Description

DNS query to known DGA-generated domain from AP-WIFI-03. Firewall matched pattern against threat intelligence feed. User: c.williams.

Alert Metadata

Alert ID
ALR-00155
Timestamp
2026-05-27T10:15:30Z
Severity
Low
Status
False Positive
Detection Source
Firewall
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
AP-WIFI-03
User Account
c.williams
Source IP
91.91.195.137
Destination IP
10.1.134.187
Origin Country
GB United Kingdom

MITRE ATT&CK Mapping

Tactic
Command and Control
Technique
T1568.002
Reference
attack.mitre.org/techniques/T1568.002

Investigation Timeline

10:15:30 Event ingested by SOC365 Engine
10:15:35 EmilyAI triage started — correlation enrichment
10:15:42 EmilyAI confidence: 81% — escalated to human analyst
10:16:14 Alert assigned to analyst: EmilyAI (auto)
10:18:05 Investigation started — querying SIEM and threat intelligence
10:24:49 Containment action taken — endpoint isolated
10:26:03 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00225 56m ago Privilege Escalation Attempt Informational Open AP-WIFI-03
ALR-00490 2h ago Pass-the-Hash Detected Low False Positive AP-WIFI-03
ALR-00182 8h ago Suspicious Scheduled Task Low Open AP-WIFI-03
ALR-00126 12h ago Malware Signature Match Informational Resolved AP-WIFI-03
ALR-00369 14h ago C2 Beacon Activity Low False Positive AP-WIFI-03