Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 15:25:28 UTC

Port Scan Detected

Medium False Positive
ALR-00427 · 2026-04-07T16:51:12Z

Description

Sequential port scan (1-1024) detected targeting FW-EDGE-01 from external IP. Endpoint Agent identified SYN scan pattern.

Alert Metadata

Alert ID
ALR-00427
Timestamp
2026-04-07T16:51:12Z
Severity
Medium
Status
False Positive
Detection Source
Endpoint Agent
Assigned Analyst
Marcus Webb

Endpoint Information

Hostname
FW-EDGE-01
User Account
m.taylor
Source IP
91.225.195.90
Destination IP
10.2.160.84
Origin Country
FR France

MITRE ATT&CK Mapping

Tactic
Reconnaissance
Technique
T1046
Reference
attack.mitre.org/techniques/T1046

Investigation Timeline

16:51:12 Event ingested by SOC365 Engine
16:51:15 EmilyAI triage started — correlation enrichment
16:51:17 EmilyAI confidence: 89% — escalated to human analyst
16:51:39 Alert assigned to analyst: Marcus Webb
16:52:12 Investigation started — querying SIEM and threat intelligence
16:56:11 Containment action taken — endpoint isolated
17:09:57 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00216 6h ago Pass-the-Hash Detected Informational Resolved FW-EDGE-01
ALR-00243 6h ago Port Scan Detected Medium Resolved WS-LAP-011
ALR-00115 9h ago Suspicious Scheduled Task Informational Open FW-EDGE-01
ALR-00063 10h ago Port Scan Detected Medium Investigating AP-WIFI-03
ALR-00099 13h ago Port Scan Detected Medium Open WS-MAC-005