Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 13:49:58 UTC

Rogue DHCP Server

Low Open
ALR-00260 · 2026-04-06T17:50:24Z

Description

Rogue DHCP server detected on VLAN 10 from SRV-SQL-01. Offering IPs in unexpected range. Email Gateway quarantined the device.

Alert Metadata

Alert ID
ALR-00260
Timestamp
2026-04-06T17:50:24Z
Severity
Low
Status
Open
Detection Source
Email Gateway
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
SRV-SQL-01
User Account
m.taylor
Source IP
45.57.148.201
Destination IP
10.2.4.30
Origin Country
UA Ukraine

MITRE ATT&CK Mapping

Tactic
Discovery
Technique
T1557.003
Reference
attack.mitre.org/techniques/T1557.003

Investigation Timeline

17:50:24 Event ingested by SOC365 Engine
17:50:27 EmilyAI triage started — correlation enrichment
17:50:34 EmilyAI confidence: 89% — escalated to human analyst
17:51:04 Alert assigned to analyst: EmilyAI (auto)
17:51:54 Investigation started — querying SIEM and threat intelligence

Related Alerts

ID Time Alert Severity Status Host
ALR-00199 2h ago Pass-the-Hash Detected Low Open SRV-SQL-01
ALR-00035 8h ago Ransomware Behaviour Detected Low False Positive SRV-SQL-01
ALR-00493 9h ago Rogue DHCP Server Medium Investigating SRV-WEB-01
ALR-00481 10h ago Rogue DHCP Server Medium False Positive WS-MAC-005
ALR-00259 12h ago Rogue DHCP Server Low Resolved SW-CORE-01