Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 18:01:06 UTC

C2 Beacon Activity

Low Investigating
ALR-00295 · 2026-05-24T14:35:25Z

Description

Suspected C2 beacon detected from SW-CORE-01. Regular 60-second interval HTTPS POST to suspicious domain. DecoyPulse blocked outbound.

Alert Metadata

Alert ID
ALR-00295
Timestamp
2026-05-24T14:35:25Z
Severity
Low
Status
Investigating
Detection Source
DecoyPulse
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
SW-CORE-01
User Account
s.jones
Source IP
194.21.62.177
Destination IP
10.3.106.149
Origin Country
IN India

MITRE ATT&CK Mapping

Tactic
Command and Control
Technique
T1071.001
Reference
attack.mitre.org/techniques/T1071.001

Investigation Timeline

14:35:25 Event ingested by SOC365 Engine
14:35:29 EmilyAI triage started — correlation enrichment
14:35:37 EmilyAI confidence: 89% — escalated to human analyst
14:35:48 Alert assigned to analyst: EmilyAI (auto)
14:36:33 Investigation started — querying SIEM and threat intelligence

Related Alerts

ID Time Alert Severity Status Host
ALR-00247 11h ago Certificate Anomaly Low Resolved SW-CORE-01
ALR-00389 12h ago Insider Threat Indicator Medium Open SW-CORE-01
ALR-00099 13h ago Certificate Anomaly Low Escalated SW-CORE-01
ALR-00100 18h ago C2 Beacon Activity Informational Open WS-PC-004
ALR-00388 20h ago C2 Beacon Activity Medium False Positive WS-LAP-010