Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 15:20:55 UTC

C2 Beacon Activity

Medium Open
ALR-00428 · 2026-04-06T07:40:16Z

Description

Suspected C2 beacon detected from WS-PC-001. Regular 60-second interval HTTPS POST to suspicious domain. DecoyPulse blocked outbound.

Alert Metadata

Alert ID
ALR-00428
Timestamp
2026-04-06T07:40:16Z
Severity
Medium
Status
Open
Detection Source
DecoyPulse
Assigned Analyst
Emma Richardson

Endpoint Information

Hostname
WS-PC-001
User Account
j.smith
Source IP
45.59.148.166
Destination IP
10.0.25.158
Origin Country
UA Ukraine

MITRE ATT&CK Mapping

Tactic
Command and Control
Technique
T1071.001
Reference
attack.mitre.org/techniques/T1071.001

Investigation Timeline

07:40:16 Event ingested by SOC365 Engine
07:40:20 EmilyAI triage started — correlation enrichment
07:40:29 EmilyAI confidence: 93% — escalated to human analyst
07:40:59 Alert assigned to analyst: Emma Richardson
07:41:34 Investigation started — querying SIEM and threat intelligence

Related Alerts

ID Time Alert Severity Status Host
ALR-00470 49m ago Ransomware Behaviour Detected Low Open WS-PC-001
ALR-00288 1h ago Insider Threat Indicator Low Resolved WS-PC-001
ALR-00015 3h ago C2 Beacon Activity High Open WS-PC-002
ALR-00002 4h ago C2 Beacon Activity Informational Open WS-PC-004
ALR-00030 7h ago Port Scan Detected Medium Escalated WS-PC-001