Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 20:13:20 UTC

Tor Exit Node Connection

Medium Escalated
ALR-00307 · 2026-05-22T18:24:03Z

Description

Connection from FW-EDGE-01 to known Tor exit node detected by Attack Surface Scanner. User 'n.clark' was active at the time.

Alert Metadata

Alert ID
ALR-00307
Timestamp
2026-05-22T18:24:03Z
Severity
Medium
Status
Escalated
Detection Source
Attack Surface Scanner
Assigned Analyst
Anika Patel

Endpoint Information

Hostname
FW-EDGE-01
User Account
n.clark
Source IP
91.73.195.233
Destination IP
10.1.125.122
Origin Country
IR Iran

MITRE ATT&CK Mapping

Tactic
Command and Control
Technique
T1090.003
Reference
attack.mitre.org/techniques/T1090.003

Investigation Timeline

18:24:03 Event ingested by SOC365 Engine
18:24:08 EmilyAI triage started — correlation enrichment
18:24:11 EmilyAI confidence: 82% — escalated to human analyst
18:24:26 Alert assigned to analyst: Anika Patel
18:25:46 Investigation started — querying SIEM and threat intelligence
18:28:01 Containment action taken — endpoint isolated
18:36:16 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00056 2h ago Malware Signature Match Low Escalated FW-EDGE-01
ALR-00446 3h ago Tor Exit Node Connection High Investigating WS-LAP-012
ALR-00127 4h ago DLP Policy Violation Medium Escalated FW-EDGE-01
ALR-00251 6h ago Tor Exit Node Connection Medium Resolved WS-PC-003
ALR-00181 7h ago Tor Exit Node Connection High Open WS-MAC-005