C2 Beacon Activity
Medium
Open
ALR-00428 · 2026-04-06T07:40:16Z
Description
Suspected C2 beacon detected from WS-PC-001. Regular 60-second interval HTTPS POST to suspicious domain. DecoyPulse blocked outbound.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
07:40:16
Event ingested by SOC365 Engine
07:40:20
EmilyAI triage started — correlation enrichment
07:40:29
EmilyAI confidence: 93% — escalated to human analyst
07:40:59
Alert assigned to analyst: Emma Richardson
07:41:34
Investigation started — querying SIEM and threat intelligence
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00470 | 49m ago | Ransomware Behaviour Detected | Low | Open | WS-PC-001 |
| ALR-00288 | 1h ago | Insider Threat Indicator | Low | Resolved | WS-PC-001 |
| ALR-00015 | 3h ago | C2 Beacon Activity | High | Open | WS-PC-002 |
| ALR-00002 | 4h ago | C2 Beacon Activity | Informational | Open | WS-PC-004 |
| ALR-00030 | 7h ago | Port Scan Detected | Medium | Escalated | WS-PC-001 |