Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 17:06:39 UTC

Certificate Anomaly

Informational Investigating
ALR-00324 · 2026-05-22T03:37:25Z

Description

TLS certificate anomaly detected on WS-PC-002. Self-signed certificate on port 443 does not match expected corporate CA chain.

Alert Metadata

Alert ID
ALR-00324
Timestamp
2026-05-22T03:37:25Z
Severity
Informational
Status
Investigating
Detection Source
EmilyAI Triage
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
WS-PC-002
User Account
d.walker
Source IP
194.218.62.107
Destination IP
10.2.132.23
Origin Country
FR France

MITRE ATT&CK Mapping

Tactic
Defence Evasion
Technique
T1553.004
Reference
attack.mitre.org/techniques/T1553.004

Investigation Timeline

03:37:25 Event ingested by SOC365 Engine
03:37:26 EmilyAI triage started — correlation enrichment
03:37:30 EmilyAI confidence: 93% — escalated to human analyst
03:37:41 Alert assigned to analyst: EmilyAI (auto)
03:39:54 Investigation started — querying SIEM and threat intelligence

Related Alerts

ID Time Alert Severity Status Host
ALR-00479 5h ago Kerberoasting Attempt Medium False Positive WS-PC-002
ALR-00338 7h ago Certificate Anomaly Low Escalated SRV-WEB-01
ALR-00342 13h ago Rogue DHCP Server Low Escalated WS-PC-002
ALR-00095 21h ago Certificate Anomaly Informational Resolved AP-WIFI-03
ALR-00427 22h ago Port Scan Detected Medium Open WS-PC-002