Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 13:50:45 UTC

C2 Beacon Activity

Medium Investigating
ALR-00457 · 2026-04-06T21:00:59Z

Description

Suspected C2 beacon detected from WS-LAP-011. Regular 60-second interval HTTPS POST to suspicious domain. DecoyPulse blocked outbound.

Alert Metadata

Alert ID
ALR-00457
Timestamp
2026-04-06T21:00:59Z
Severity
Medium
Status
Investigating
Detection Source
DecoyPulse
Assigned Analyst
Marcus Webb

Endpoint Information

Hostname
WS-LAP-011
User Account
c.williams
Source IP
45.170.148.59
Destination IP
10.1.21.150
Origin Country
GB United Kingdom

MITRE ATT&CK Mapping

Tactic
Command and Control
Technique
T1071.001
Reference
attack.mitre.org/techniques/T1071.001

Investigation Timeline

21:00:59 Event ingested by SOC365 Engine
21:01:01 EmilyAI triage started — correlation enrichment
21:01:09 EmilyAI confidence: 84% — escalated to human analyst
21:01:34 Alert assigned to analyst: Marcus Webb
21:02:32 Investigation started — querying SIEM and threat intelligence

Related Alerts

ID Time Alert Severity Status Host
ALR-00069 2h ago Insider Threat Indicator Medium Open WS-LAP-011
ALR-00001 3h ago C2 Beacon Activity Informational Escalated WS-PC-001
ALR-00184 10h ago C2 Beacon Activity Medium Resolved WS-LAP-012
ALR-00387 12h ago C2 Beacon Activity Medium Investigating SW-CORE-01
ALR-00216 14h ago DecoyPulse Honeypot Triggered Low Investigating WS-LAP-011