Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 17:10:57 UTC

Tor Exit Node Connection

High Investigating
ALR-00234 · 2026-05-27T04:38:29Z

Description

Connection from WS-PC-004 to known Tor exit node detected by DLP Module. User 'c.williams' was active at the time.

Alert Metadata

Alert ID
ALR-00234
Timestamp
2026-05-27T04:38:29Z
Severity
High
Status
Investigating
Detection Source
DLP Module
Assigned Analyst
Marcus Webb

Endpoint Information

Hostname
WS-PC-004
User Account
c.williams
Source IP
194.182.62.227
Destination IP
10.0.214.208
Origin Country
RU Russia

MITRE ATT&CK Mapping

Tactic
Command and Control
Technique
T1090.003
Reference
attack.mitre.org/techniques/T1090.003

Investigation Timeline

04:38:29 Event ingested by SOC365 Engine
04:38:31 EmilyAI triage started — correlation enrichment
04:38:41 EmilyAI confidence: 94% — escalated to human analyst
04:39:11 Alert assigned to analyst: Marcus Webb
04:40:51 Investigation started — querying SIEM and threat intelligence

Related Alerts

ID Time Alert Severity Status Host
ALR-00079 1h ago Privilege Escalation Attempt Informational False Positive WS-PC-004
ALR-00203 10h ago Tor Exit Node Connection Informational False Positive WS-PC-001
ALR-00345 12h ago C2 Beacon Activity Medium Open WS-PC-004
ALR-00379 20h ago Tor Exit Node Connection Informational False Positive SW-CORE-01
ALR-00111 22h ago Tor Exit Node Connection Informational Resolved WS-PC-002