Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 20:13:06 UTC

C2 Beacon Activity

Low Escalated
ALR-00329 · 2026-05-21T10:14:53Z

Description

Suspected C2 beacon detected from WS-PC-003. Regular 60-second interval HTTPS POST to suspicious domain. DLP Module blocked outbound.

Alert Metadata

Alert ID
ALR-00329
Timestamp
2026-05-21T10:14:53Z
Severity
Low
Status
Escalated
Detection Source
DLP Module
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
WS-PC-003
User Account
s.jones
Source IP
91.137.195.153
Destination IP
10.3.59.16
Origin Country
CN China

MITRE ATT&CK Mapping

Tactic
Command and Control
Technique
T1071.001
Reference
attack.mitre.org/techniques/T1071.001

Investigation Timeline

10:14:53 Event ingested by SOC365 Engine
10:14:56 EmilyAI triage started — correlation enrichment
10:14:59 EmilyAI confidence: 90% — escalated to human analyst
10:15:14 Alert assigned to analyst: EmilyAI (auto)
10:15:42 Investigation started — querying SIEM and threat intelligence
10:24:33 Containment action taken — endpoint isolated
10:25:30 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00311 17m ago Ransomware Behaviour Detected Medium Escalated WS-PC-003
ALR-00263 5h ago C2 Beacon Activity Low Open SRV-APP-01
ALR-00251 6h ago Tor Exit Node Connection Medium Resolved WS-PC-003
ALR-00035 10h ago C2 Beacon Activity High Open WS-MAC-005
ALR-00145 12h ago C2 Beacon Activity Informational Investigating WS-PC-002