Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 18:05:30 UTC

Rogue DHCP Server

Informational False Positive
ALR-00198 · 2026-05-22T00:03:31Z

Description

Rogue DHCP server detected on VLAN 10 from SRV-MAIL-01. Offering IPs in unexpected range. DLP Module quarantined the device.

Alert Metadata

Alert ID
ALR-00198
Timestamp
2026-05-22T00:03:31Z
Severity
Informational
Status
False Positive
Detection Source
DLP Module
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
SRV-MAIL-01
User Account
k.brown
Source IP
45.168.148.219
Destination IP
10.3.203.254
Origin Country
BR Brazil

MITRE ATT&CK Mapping

Tactic
Discovery
Technique
T1557.003
Reference
attack.mitre.org/techniques/T1557.003

Investigation Timeline

00:03:31 Event ingested by SOC365 Engine
00:03:34 EmilyAI triage started — correlation enrichment
00:03:45 EmilyAI confidence: 78% — escalated to human analyst
00:04:08 Alert assigned to analyst: EmilyAI (auto)
00:04:20 Investigation started — querying SIEM and threat intelligence
00:08:11 Containment action taken — endpoint isolated
00:18:38 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00500 2h ago Rogue DHCP Server Medium Open SRV-WEB-01
ALR-00002 9h ago Anomalous DNS Query Informational False Positive SRV-MAIL-01
ALR-00103 10h ago Rogue DHCP Server Low False Positive WS-PC-003
ALR-00418 19h ago Rogue DHCP Server Medium False Positive WS-LAP-010
ALR-00134 20h ago Privilege Escalation Attempt Medium Escalated SRV-MAIL-01