Anomalous DNS Query
Low
Investigating
ALR-00335 · 2026-05-22T09:23:30Z
Description
DNS query to known DGA-generated domain from WS-PC-004. Endpoint Agent matched pattern against threat intelligence feed. User: p.thomas.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
09:23:30
Event ingested by SOC365 Engine
09:23:33
EmilyAI triage started — correlation enrichment
09:23:40
EmilyAI confidence: 82% — escalated to human analyst
09:23:51
Alert assigned to analyst: EmilyAI (auto)
09:25:33
Investigation started — querying SIEM and threat intelligence
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00385 | 21h ago | Anomalous DNS Query | High | Investigating | WS-PC-002 |
| ALR-00418 | 1d ago | Port Scan Detected | Critical | Escalated | WS-PC-004 |
| ALR-00421 | 1d ago | Anomalous DNS Query | Informational | Investigating | SRV-FILE-01 |
| ALR-00311 | 1d ago | Anomalous DNS Query | High | Escalated | SRV-APP-01 |
| ALR-00247 | 1d ago | Anomalous DNS Query | Low | Resolved | WS-PC-006 |