Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 16:51:18 UTC

Tor Exit Node Connection

Low Resolved
ALR-00436 · 2026-04-10T17:20:53Z

Description

Connection from SRV-DC-01 to known Tor exit node detected by EmilyAI Triage. User 'e.evans' was active at the time.

Alert Metadata

Alert ID
ALR-00436
Timestamp
2026-04-10T17:20:53Z
Severity
Low
Status
Resolved
Detection Source
EmilyAI Triage
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
SRV-DC-01
User Account
e.evans
Source IP
103.109.216.66
Destination IP
10.1.119.176
Origin Country
RO Romania

MITRE ATT&CK Mapping

Tactic
Command and Control
Technique
T1090.003
Reference
attack.mitre.org/techniques/T1090.003

Investigation Timeline

17:20:53 Event ingested by SOC365 Engine
17:20:58 EmilyAI triage started — correlation enrichment
17:21:07 EmilyAI confidence: 93% — escalated to human analyst
17:21:30 Alert assigned to analyst: EmilyAI (auto)
17:22:03 Investigation started — querying SIEM and threat intelligence
17:28:43 Containment action taken — endpoint isolated
17:31:33 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00054 7m ago Ransomware Behaviour Detected Medium False Positive SRV-DC-01
ALR-00197 1h ago Certificate Anomaly Informational Investigating SRV-DC-01
ALR-00090 1h ago C2 Beacon Activity Low False Positive SRV-DC-01
ALR-00258 6h ago Tor Exit Node Connection Informational False Positive SRV-DC-01
ALR-00271 9h ago Shadow IT Discovery Medium False Positive SRV-DC-01