C2 Beacon Activity
Informational
Escalated
ALR-00332 · 2026-04-06T08:26:01Z
Description
Suspected C2 beacon detected from SRV-APP-01. Regular 60-second interval HTTPS POST to suspicious domain. Firewall blocked outbound.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
08:26:01
Event ingested by SOC365 Engine
08:26:05
EmilyAI triage started — correlation enrichment
08:26:08
EmilyAI confidence: 86% — escalated to human analyst
08:26:43
Alert assigned to analyst: EmilyAI (auto)
08:28:58
Investigation started — querying SIEM and threat intelligence
08:32:15
Containment action taken — endpoint isolated
08:37:46
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00072 | 1h ago | C2 Beacon Activity | Medium | Open | WS-LAP-010 |
| ALR-00131 | 23h ago | C2 Beacon Activity | Medium | Open | SRV-BACKUP-01 |
| ALR-00178 | 1d ago | C2 Beacon Activity | High | Escalated | SW-CORE-01 |
| ALR-00185 | 1d ago | C2 Beacon Activity | Informational | Escalated | WS-LAP-011 |
| ALR-00152 | 1d ago | Credential Stuffing Attempt | High | Investigating | SRV-APP-01 |