Certificate Anomaly
Medium
Resolved
ALR-00212 · 2026-04-09T16:09:23Z
Description
TLS certificate anomaly detected on SRV-DC-01. Self-signed certificate on port 443 does not match expected corporate CA chain.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
16:09:23
Event ingested by SOC365 Engine
16:09:26
EmilyAI triage started — correlation enrichment
16:09:33
EmilyAI confidence: 97% — escalated to human analyst
16:10:00
Alert assigned to analyst: James Okonkwo
16:10:20
Investigation started — querying SIEM and threat intelligence
16:16:16
Containment action taken — endpoint isolated
16:24:21
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00055 | 11h ago | Certificate Anomaly | High | Investigating | WS-PC-003 |
| ALR-00301 | 20h ago | Certificate Anomaly | Medium | Investigating | SRV-BACKUP-01 |
| ALR-00423 | 1d ago | Unauthorised USB Device | Informational | False Positive | SRV-DC-01 |
| ALR-00468 | 1d ago | Unusual Outbound Traffic | Medium | Escalated | SRV-DC-01 |
| ALR-00303 | 1d ago | Suspicious PowerShell Execution | High | Escalated | SRV-DC-01 |