Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 18:05:36 UTC

Ransomware Behaviour Detected

Informational False Positive
ALR-00275 · 2026-05-26T20:11:25Z

Description

File encryption behaviour detected on WS-PC-001. 142 files renamed with .locked extension in 30 seconds. EmilyAI Triage isolated endpoint.

Alert Metadata

Alert ID
ALR-00275
Timestamp
2026-05-26T20:11:25Z
Severity
Informational
Status
False Positive
Detection Source
EmilyAI Triage
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
WS-PC-001
User Account
p.thomas
Source IP
103.17.216.89
Destination IP
10.0.22.54
Origin Country
VN Vietnam

MITRE ATT&CK Mapping

Tactic
Impact
Technique
T1486
Reference
attack.mitre.org/techniques/T1486

Investigation Timeline

20:11:25 Event ingested by SOC365 Engine
20:11:28 EmilyAI triage started — correlation enrichment
20:11:35 EmilyAI confidence: 84% — escalated to human analyst
20:11:55 Alert assigned to analyst: EmilyAI (auto)
20:13:56 Investigation started — querying SIEM and threat intelligence
20:14:42 Containment action taken — endpoint isolated
20:23:15 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00416 20h ago Privilege Escalation Attempt Low False Positive WS-PC-001
ALR-00152 21h ago Kerberoasting Attempt Informational False Positive WS-PC-001
ALR-00199 21h ago Kerberoasting Attempt Low Escalated WS-PC-001
ALR-00176 1d ago Ransomware Behaviour Detected Medium False Positive WS-PC-002
ALR-00378 1d ago Ransomware Behaviour Detected Medium Escalated SRV-MAIL-01