Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 16:57:09 UTC

C2 Beacon Activity

Informational Escalated
ALR-00240 · 2026-04-10T19:40:06Z

Description

Suspected C2 beacon detected from WS-LAP-011. Regular 60-second interval HTTPS POST to suspicious domain. Endpoint Agent blocked outbound.

Alert Metadata

Alert ID
ALR-00240
Timestamp
2026-04-10T19:40:06Z
Severity
Informational
Status
Escalated
Detection Source
Endpoint Agent
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
WS-LAP-011
User Account
n.clark
Source IP
91.44.195.208
Destination IP
10.1.55.6
Origin Country
RU Russia

MITRE ATT&CK Mapping

Tactic
Command and Control
Technique
T1071.001
Reference
attack.mitre.org/techniques/T1071.001

Investigation Timeline

19:40:06 Event ingested by SOC365 Engine
19:40:11 EmilyAI triage started — correlation enrichment
19:40:18 EmilyAI confidence: 90% — escalated to human analyst
19:40:22 Alert assigned to analyst: EmilyAI (auto)
19:41:14 Investigation started — querying SIEM and threat intelligence
19:49:35 Containment action taken — endpoint isolated
19:51:11 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00386 1h ago C2 Beacon Activity Medium Escalated SRV-DC-01
ALR-00117 1h ago Certificate Anomaly Low Open WS-LAP-011
ALR-00288 8h ago C2 Beacon Activity Informational False Positive AP-WIFI-03
ALR-00438 10h ago C2 Beacon Activity Low Resolved WS-PC-002
ALR-00083 13h ago Kerberoasting Attempt Informational Escalated WS-LAP-011