Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 17:12:37 UTC

C2 Beacon Activity

Informational Investigating
ALR-00341 · 2026-05-24T16:50:31Z

Description

Suspected C2 beacon detected from SRV-BACKUP-01. Regular 60-second interval HTTPS POST to suspicious domain. Attack Surface Scanner blocked outbound.

Alert Metadata

Alert ID
ALR-00341
Timestamp
2026-05-24T16:50:31Z
Severity
Informational
Status
Investigating
Detection Source
Attack Surface Scanner
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
SRV-BACKUP-01
User Account
system
Source IP
194.147.62.100
Destination IP
10.0.253.142
Origin Country
UA Ukraine

MITRE ATT&CK Mapping

Tactic
Command and Control
Technique
T1071.001
Reference
attack.mitre.org/techniques/T1071.001

Investigation Timeline

16:50:31 Event ingested by SOC365 Engine
16:50:33 EmilyAI triage started — correlation enrichment
16:50:41 EmilyAI confidence: 79% — escalated to human analyst
16:50:50 Alert assigned to analyst: EmilyAI (auto)
16:51:20 Investigation started — querying SIEM and threat intelligence

Related Alerts

ID Time Alert Severity Status Host
ALR-00235 2h ago Failed MFA Challenge Critical Investigating SRV-BACKUP-01
ALR-00071 4h ago Suspicious PowerShell Execution Low Resolved SRV-BACKUP-01
ALR-00422 5h ago C2 Beacon Activity Informational Open SRV-BACKUP-01
ALR-00010 7h ago Brute Force SSH Informational False Positive SRV-BACKUP-01
ALR-00189 12h ago C2 Beacon Activity Low Escalated WS-PC-001