Rogue DHCP Server
Informational
False Positive
ALR-00198 · 2026-05-22T00:03:31Z
Description
Rogue DHCP server detected on VLAN 10 from SRV-MAIL-01. Offering IPs in unexpected range. DLP Module quarantined the device.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
00:03:31
Event ingested by SOC365 Engine
00:03:34
EmilyAI triage started — correlation enrichment
00:03:45
EmilyAI confidence: 78% — escalated to human analyst
00:04:08
Alert assigned to analyst: EmilyAI (auto)
00:04:20
Investigation started — querying SIEM and threat intelligence
00:08:11
Containment action taken — endpoint isolated
00:18:38
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00500 | 2h ago | Rogue DHCP Server | Medium | Open | SRV-WEB-01 |
| ALR-00002 | 9h ago | Anomalous DNS Query | Informational | False Positive | SRV-MAIL-01 |
| ALR-00103 | 10h ago | Rogue DHCP Server | Low | False Positive | WS-PC-003 |
| ALR-00418 | 19h ago | Rogue DHCP Server | Medium | False Positive | WS-LAP-010 |
| ALR-00134 | 20h ago | Privilege Escalation Attempt | Medium | Escalated | SRV-MAIL-01 |