Anomalous DNS Query
Medium
Investigating
ALR-00168 · 2026-04-09T07:35:54Z
Description
DNS query to known DGA-generated domain from SRV-DC-01. SOC365 Engine matched pattern against threat intelligence feed. User: p.thomas.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
07:35:54
Event ingested by SOC365 Engine
07:35:56
EmilyAI triage started — correlation enrichment
07:36:08
EmilyAI confidence: 91% — escalated to human analyst
07:36:33
Alert assigned to analyst: Marcus Webb
07:36:44
Investigation started — querying SIEM and threat intelligence
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00205 | 7h ago | Privilege Escalation Attempt | High | Open | SRV-DC-01 |
| ALR-00192 | 10h ago | Anomalous DNS Query | Low | Resolved | WS-PC-006 |
| ALR-00292 | 11h ago | Rogue DHCP Server | Medium | False Positive | SRV-DC-01 |
| ALR-00209 | 18h ago | DLP Policy Violation | Informational | False Positive | SRV-DC-01 |
| ALR-00353 | 19h ago | Anomalous DNS Query | Low | Open | SRV-DC-01 |