Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 15:27:00 UTC

C2 Beacon Activity

Low Open
ALR-00434 · 2026-04-07T19:21:02Z

Description

Suspected C2 beacon detected from WS-PC-002. Regular 60-second interval HTTPS POST to suspicious domain. Dark Web Monitor blocked outbound.

Alert Metadata

Alert ID
ALR-00434
Timestamp
2026-04-07T19:21:02Z
Severity
Low
Status
Open
Detection Source
Dark Web Monitor
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
WS-PC-002
User Account
a.wilson
Source IP
91.65.195.171
Destination IP
10.2.85.70
Origin Country
IR Iran

MITRE ATT&CK Mapping

Tactic
Command and Control
Technique
T1071.001
Reference
attack.mitre.org/techniques/T1071.001

Investigation Timeline

19:21:02 Event ingested by SOC365 Engine
19:21:05 EmilyAI triage started — correlation enrichment
19:21:11 EmilyAI confidence: 82% — escalated to human analyst
19:21:45 Alert assigned to analyst: EmilyAI (auto)
19:23:34 Investigation started — querying SIEM and threat intelligence

Related Alerts

ID Time Alert Severity Status Host
ALR-00367 2h ago Tor Exit Node Connection Medium Open WS-PC-002
ALR-00137 6h ago Unauthorised USB Device Informational Open WS-PC-002
ALR-00011 6h ago C2 Beacon Activity Informational Investigating SRV-BACKUP-01
ALR-00399 8h ago DecoyPulse Honeypot Triggered Low Escalated WS-PC-002
ALR-00193 9h ago C2 Beacon Activity Medium Investigating WS-PC-004