Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 13:50:46 UTC

C2 Beacon Activity

Medium Investigating
ALR-00387 · 2026-04-12T01:14:44Z

Description

Suspected C2 beacon detected from SW-CORE-01. Regular 60-second interval HTTPS POST to suspicious domain. DecoyPulse blocked outbound.

Alert Metadata

Alert ID
ALR-00387
Timestamp
2026-04-12T01:14:44Z
Severity
Medium
Status
Investigating
Detection Source
DecoyPulse
Assigned Analyst
Anika Patel

Endpoint Information

Hostname
SW-CORE-01
User Account
n.clark
Source IP
91.235.195.132
Destination IP
10.3.149.163
Origin Country
US United States

MITRE ATT&CK Mapping

Tactic
Command and Control
Technique
T1071.001
Reference
attack.mitre.org/techniques/T1071.001

Investigation Timeline

01:14:44 Event ingested by SOC365 Engine
01:14:47 EmilyAI triage started — correlation enrichment
01:14:57 EmilyAI confidence: 85% — escalated to human analyst
01:15:05 Alert assigned to analyst: Anika Patel
01:17:11 Investigation started — querying SIEM and threat intelligence

Related Alerts

ID Time Alert Severity Status Host
ALR-00001 3h ago C2 Beacon Activity Informational Escalated WS-PC-001
ALR-00237 7h ago Unusual Outbound Traffic Informational False Positive SW-CORE-01
ALR-00184 10h ago C2 Beacon Activity Medium Resolved WS-LAP-012
ALR-00306 11h ago Insider Threat Indicator Low Investigating SW-CORE-01
ALR-00477 19h ago Malware Signature Match Informational Investigating SW-CORE-01