Rogue DHCP Server
Informational
Open
ALR-00452 · 2026-05-27T04:07:38Z
Description
Rogue DHCP server detected on VLAN 10 from SRV-APP-01. Offering IPs in unexpected range. Dark Web Monitor quarantined the device.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
04:07:38
Event ingested by SOC365 Engine
04:07:39
EmilyAI triage started — correlation enrichment
04:07:51
EmilyAI confidence: 84% — escalated to human analyst
04:08:16
Alert assigned to analyst: EmilyAI (auto)
04:10:11
Investigation started — querying SIEM and threat intelligence
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00307 | 33m ago | Unauthorised USB Device | Low | Resolved | SRV-APP-01 |
| ALR-00269 | 9h ago | Rogue DHCP Server | Low | Open | VM-DEV-01 |
| ALR-00236 | 10h ago | Rogue DHCP Server | Informational | Investigating | WS-MAC-005 |
| ALR-00255 | 16h ago | Rogue DHCP Server | High | Investigating | SRV-MAIL-01 |
| ALR-00166 | 19h ago | Brute Force SSH | Low | Escalated | SRV-APP-01 |