Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 17:05:34 UTC

Ransomware Behaviour Detected

Informational Open
ALR-00342 · 2026-05-25T21:57:18Z

Description

File encryption behaviour detected on SRV-MAIL-01. 142 files renamed with .locked extension in 30 seconds. Network IDS isolated endpoint.

Alert Metadata

Alert ID
ALR-00342
Timestamp
2026-05-25T21:57:18Z
Severity
Informational
Status
Open
Detection Source
Network IDS
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
SRV-MAIL-01
User Account
system
Source IP
194.108.62.34
Destination IP
10.0.26.89
Origin Country
NG Nigeria

MITRE ATT&CK Mapping

Tactic
Impact
Technique
T1486
Reference
attack.mitre.org/techniques/T1486

Investigation Timeline

21:57:18 Event ingested by SOC365 Engine
21:57:19 EmilyAI triage started — correlation enrichment
21:57:30 EmilyAI confidence: 85% — escalated to human analyst
21:57:40 Alert assigned to analyst: EmilyAI (auto)
21:59:44 Investigation started — querying SIEM and threat intelligence

Related Alerts

ID Time Alert Severity Status Host
ALR-00370 2h ago Ransomware Behaviour Detected Informational Resolved WS-PC-006
ALR-00438 3h ago Suspicious Scheduled Task Low Escalated SRV-MAIL-01
ALR-00028 6h ago Ransomware Behaviour Detected Low Investigating SRV-SQL-01
ALR-00040 7h ago C2 Beacon Activity Medium Escalated SRV-MAIL-01
ALR-00018 9h ago Ransomware Behaviour Detected Informational Resolved SRV-SQL-01