Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 18:19:48 UTC

Tor Exit Node Connection

Medium Open
ALR-00410 · 2026-05-24T02:45:34Z

Description

Connection from WS-PC-003 to known Tor exit node detected by Cloud Connector. User 'p.thomas' was active at the time.

Alert Metadata

Alert ID
ALR-00410
Timestamp
2026-05-24T02:45:34Z
Severity
Medium
Status
Open
Detection Source
Cloud Connector
Assigned Analyst
Anika Patel

Endpoint Information

Hostname
WS-PC-003
User Account
p.thomas
Source IP
91.46.195.92
Destination IP
10.0.92.177
Origin Country
NL Netherlands

MITRE ATT&CK Mapping

Tactic
Command and Control
Technique
T1090.003
Reference
attack.mitre.org/techniques/T1090.003

Investigation Timeline

02:45:34 Event ingested by SOC365 Engine
02:45:39 EmilyAI triage started — correlation enrichment
02:45:45 EmilyAI confidence: 91% — escalated to human analyst
02:45:54 Alert assigned to analyst: Anika Patel
02:47:50 Investigation started — querying SIEM and threat intelligence

Related Alerts

ID Time Alert Severity Status Host
ALR-00383 2h ago Credential Stuffing Attempt High Open WS-PC-003
ALR-00107 5h ago Tor Exit Node Connection High Investigating WS-LAP-010
ALR-00454 9h ago Credential Stuffing Attempt Medium Investigating WS-PC-003
ALR-00317 15h ago Tor Exit Node Connection Low Open SRV-APP-01
ALR-00025 18h ago Unusual Outbound Traffic High Escalated WS-PC-003