Certificate Anomaly
Low
False Positive
ALR-00465 · 2026-04-10T00:22:21Z
Description
TLS certificate anomaly detected on SRV-BACKUP-01. Self-signed certificate on port 443 does not match expected corporate CA chain.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
00:22:21
Event ingested by SOC365 Engine
00:22:23
EmilyAI triage started — correlation enrichment
00:22:29
EmilyAI confidence: 82% — escalated to human analyst
00:22:53
Alert assigned to analyst: EmilyAI (auto)
00:25:20
Investigation started — querying SIEM and threat intelligence
00:27:51
Containment action taken — endpoint isolated
00:39:18
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00441 | 3h ago | Pass-the-Hash Detected | Medium | Investigating | SRV-BACKUP-01 |
| ALR-00134 | 10h ago | Certificate Anomaly | Medium | Escalated | WS-PC-003 |
| ALR-00299 | 11h ago | Failed MFA Challenge | Low | False Positive | SRV-BACKUP-01 |
| ALR-00113 | 23h ago | Certificate Anomaly | Low | Escalated | SRV-SQL-01 |
| ALR-00210 | 1d ago | DecoyPulse Honeypot Triggered | Low | Open | SRV-BACKUP-01 |