Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 19:25:21 UTC

C2 Beacon Activity

Medium Open
ALR-00391 · 2026-05-21T17:37:25Z

Description

Suspected C2 beacon detected from WS-PC-003. Regular 60-second interval HTTPS POST to suspicious domain. Email Gateway blocked outbound.

Alert Metadata

Alert ID
ALR-00391
Timestamp
2026-05-21T17:37:25Z
Severity
Medium
Status
Open
Detection Source
Email Gateway
Assigned Analyst
Sarah Chen

Endpoint Information

Hostname
WS-PC-003
User Account
m.taylor
Source IP
194.155.62.203
Destination IP
10.2.99.151
Origin Country
US United States

MITRE ATT&CK Mapping

Tactic
Command and Control
Technique
T1071.001
Reference
attack.mitre.org/techniques/T1071.001

Investigation Timeline

17:37:25 Event ingested by SOC365 Engine
17:37:30 EmilyAI triage started — correlation enrichment
17:37:31 EmilyAI confidence: 87% — escalated to human analyst
17:37:47 Alert assigned to analyst: Sarah Chen
17:39:24 Investigation started — querying SIEM and threat intelligence

Related Alerts

ID Time Alert Severity Status Host
ALR-00439 2h ago C2 Beacon Activity Medium Open FW-EDGE-01
ALR-00034 13h ago Unusual Outbound Traffic Medium Resolved WS-PC-003
ALR-00119 15h ago C2 Beacon Activity Low Investigating SRV-SQL-01
ALR-00286 18h ago Malware Signature Match Informational False Positive WS-PC-003
ALR-00096 22h ago Shadow IT Discovery Informational False Positive WS-PC-003