Rogue DHCP Server
Medium
Resolved
ALR-00369 · 2026-05-21T04:06:05Z
Description
Rogue DHCP server detected on VLAN 10 from WS-PC-003. Offering IPs in unexpected range. SOC365 Engine quarantined the device.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
04:06:05
Event ingested by SOC365 Engine
04:06:10
EmilyAI triage started — correlation enrichment
04:06:16
EmilyAI confidence: 84% — escalated to human analyst
04:06:48
Alert assigned to analyst: Anika Patel
04:08:47
Investigation started — querying SIEM and threat intelligence
04:09:47
Containment action taken — endpoint isolated
04:25:27
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00162 | 9h ago | Rogue DHCP Server | Critical | Investigating | WS-PC-001 |
| ALR-00026 | 18h ago | Data Exfiltration Attempt | Low | Escalated | WS-PC-003 |
| ALR-00138 | 1d ago | Rogue DHCP Server | Medium | Open | WS-PC-001 |
| ALR-00277 | 1d ago | Ransomware Behaviour Detected | Informational | Escalated | WS-PC-003 |
| ALR-00427 | 1d ago | Phishing Email Blocked | Medium | Resolved | WS-PC-003 |