Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 17:09:53 UTC

Anomalous DNS Query

Low Resolved
ALR-00393 · 2026-05-22T23:41:21Z

Description

DNS query to known DGA-generated domain from SW-CORE-01. Cloud Connector matched pattern against threat intelligence feed. User: f.hall.

Alert Metadata

Alert ID
ALR-00393
Timestamp
2026-05-22T23:41:21Z
Severity
Low
Status
Resolved
Detection Source
Cloud Connector
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
SW-CORE-01
User Account
f.hall
Source IP
194.89.62.205
Destination IP
10.1.72.181
Origin Country
NG Nigeria

MITRE ATT&CK Mapping

Tactic
Command and Control
Technique
T1568.002
Reference
attack.mitre.org/techniques/T1568.002

Investigation Timeline

23:41:21 Event ingested by SOC365 Engine
23:41:22 EmilyAI triage started — correlation enrichment
23:41:35 EmilyAI confidence: 89% — escalated to human analyst
23:42:02 Alert assigned to analyst: EmilyAI (auto)
23:43:37 Investigation started — querying SIEM and threat intelligence
23:45:11 Containment action taken — endpoint isolated
23:56:06 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00461 1m ago Data Exfiltration Attempt Informational Investigating SW-CORE-01
ALR-00268 28m ago Rogue DHCP Server Low Investigating SW-CORE-01
ALR-00488 1h ago Anomalous DNS Query High Investigating VM-DEV-01
ALR-00164 4h ago Kerberoasting Attempt Informational Escalated SW-CORE-01
ALR-00236 8h ago Suspicious Scheduled Task Low False Positive SW-CORE-01