Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 20:10:42 UTC

Port Scan Detected

Informational Resolved
ALR-00227 · 2026-05-24T17:05:57Z

Description

Sequential port scan (1-1024) detected targeting SRV-FILE-01 from external IP. Email Gateway identified SYN scan pattern.

Alert Metadata

Alert ID
ALR-00227
Timestamp
2026-05-24T17:05:57Z
Severity
Informational
Status
Resolved
Detection Source
Email Gateway
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
SRV-FILE-01
User Account
a.wilson
Source IP
194.247.62.88
Destination IP
10.2.35.194
Origin Country
KP North Korea

MITRE ATT&CK Mapping

Tactic
Reconnaissance
Technique
T1046
Reference
attack.mitre.org/techniques/T1046

Investigation Timeline

17:05:57 Event ingested by SOC365 Engine
17:05:58 EmilyAI triage started — correlation enrichment
17:06:05 EmilyAI confidence: 93% — escalated to human analyst
17:06:19 Alert assigned to analyst: EmilyAI (auto)
17:08:50 Investigation started — querying SIEM and threat intelligence
17:15:55 Containment action taken — endpoint isolated
17:21:17 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00342 8h ago Port Scan Detected Low Investigating WS-PC-001
ALR-00406 12h ago DLP Policy Violation Low Escalated SRV-FILE-01
ALR-00185 14h ago Port Scan Detected Low Resolved WS-PC-006
ALR-00431 14h ago Port Scan Detected Informational Resolved SRV-WEB-01
ALR-00023 16h ago Port Scan Detected High Investigating WS-MAC-005