Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 17:05:33 UTC

Rogue DHCP Server

Medium Resolved
ALR-00369 · 2026-05-21T04:06:05Z

Description

Rogue DHCP server detected on VLAN 10 from WS-PC-003. Offering IPs in unexpected range. SOC365 Engine quarantined the device.

Alert Metadata

Alert ID
ALR-00369
Timestamp
2026-05-21T04:06:05Z
Severity
Medium
Status
Resolved
Detection Source
SOC365 Engine
Assigned Analyst
Anika Patel

Endpoint Information

Hostname
WS-PC-003
User Account
e.evans
Source IP
45.240.148.16
Destination IP
10.3.5.75
Origin Country
CN China

MITRE ATT&CK Mapping

Tactic
Discovery
Technique
T1557.003
Reference
attack.mitre.org/techniques/T1557.003

Investigation Timeline

04:06:05 Event ingested by SOC365 Engine
04:06:10 EmilyAI triage started — correlation enrichment
04:06:16 EmilyAI confidence: 84% — escalated to human analyst
04:06:48 Alert assigned to analyst: Anika Patel
04:08:47 Investigation started — querying SIEM and threat intelligence
04:09:47 Containment action taken — endpoint isolated
04:25:27 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00162 9h ago Rogue DHCP Server Critical Investigating WS-PC-001
ALR-00026 18h ago Data Exfiltration Attempt Low Escalated WS-PC-003
ALR-00138 1d ago Rogue DHCP Server Medium Open WS-PC-001
ALR-00277 1d ago Ransomware Behaviour Detected Informational Escalated WS-PC-003
ALR-00427 1d ago Phishing Email Blocked Medium Resolved WS-PC-003