Certificate Anomaly
Medium
Escalated
ALR-00364 · 2026-05-26T12:07:39Z
Description
TLS certificate anomaly detected on SRV-WEB-01. Self-signed certificate on port 443 does not match expected corporate CA chain.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
12:07:39
Event ingested by SOC365 Engine
12:07:40
EmilyAI triage started — correlation enrichment
12:07:53
EmilyAI confidence: 88% — escalated to human analyst
12:08:23
Alert assigned to analyst: Anika Patel
12:10:39
Investigation started — querying SIEM and threat intelligence
12:16:51
Containment action taken — endpoint isolated
12:26:07
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00256 | 4h ago | Privilege Escalation Attempt | Low | Investigating | SRV-WEB-01 |
| ALR-00219 | 11h ago | Credential Stuffing Attempt | High | Investigating | SRV-WEB-01 |
| ALR-00080 | 14h ago | Data Exfiltration Attempt | Informational | Resolved | SRV-WEB-01 |
| ALR-00421 | 15h ago | Suspicious PowerShell Execution | Medium | Escalated | SRV-WEB-01 |
| ALR-00281 | 16h ago | C2 Beacon Activity | Low | False Positive | SRV-WEB-01 |