Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 16:52:58 UTC

Certificate Anomaly

Low False Positive
ALR-00465 · 2026-04-10T00:22:21Z

Description

TLS certificate anomaly detected on SRV-BACKUP-01. Self-signed certificate on port 443 does not match expected corporate CA chain.

Alert Metadata

Alert ID
ALR-00465
Timestamp
2026-04-10T00:22:21Z
Severity
Low
Status
False Positive
Detection Source
DecoyPulse
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
SRV-BACKUP-01
User Account
f.hall
Source IP
91.137.195.113
Destination IP
10.2.128.228
Origin Country
KP North Korea

MITRE ATT&CK Mapping

Tactic
Defence Evasion
Technique
T1553.004
Reference
attack.mitre.org/techniques/T1553.004

Investigation Timeline

00:22:21 Event ingested by SOC365 Engine
00:22:23 EmilyAI triage started — correlation enrichment
00:22:29 EmilyAI confidence: 82% — escalated to human analyst
00:22:53 Alert assigned to analyst: EmilyAI (auto)
00:25:20 Investigation started — querying SIEM and threat intelligence
00:27:51 Containment action taken — endpoint isolated
00:39:18 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00441 3h ago Pass-the-Hash Detected Medium Investigating SRV-BACKUP-01
ALR-00134 10h ago Certificate Anomaly Medium Escalated WS-PC-003
ALR-00299 11h ago Failed MFA Challenge Low False Positive SRV-BACKUP-01
ALR-00113 23h ago Certificate Anomaly Low Escalated SRV-SQL-01
ALR-00210 1d ago DecoyPulse Honeypot Triggered Low Open SRV-BACKUP-01