Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 13:57:13 UTC

Malware Signature Match

Medium False Positive
ALR-00466 · 2026-04-07T08:34:37Z

Description

Known malware signature (Emotet variant) detected in file on SRV-FILE-01. SOC365 Engine quarantined the file. User context: d.walker.

Alert Metadata

Alert ID
ALR-00466
Timestamp
2026-04-07T08:34:37Z
Severity
Medium
Status
False Positive
Detection Source
SOC365 Engine
Assigned Analyst
Emma Richardson

Endpoint Information

Hostname
SRV-FILE-01
User Account
d.walker
Source IP
185.177.220.164
Destination IP
10.3.101.186
Origin Country
DE Germany

MITRE ATT&CK Mapping

Tactic
Execution
Technique
T1204.002
Reference
attack.mitre.org/techniques/T1204.002

Investigation Timeline

08:34:37 Event ingested by SOC365 Engine
08:34:40 EmilyAI triage started — correlation enrichment
08:34:44 EmilyAI confidence: 98% — escalated to human analyst
08:35:19 Alert assigned to analyst: Emma Richardson
08:37:12 Investigation started — querying SIEM and threat intelligence
08:39:52 Containment action taken — endpoint isolated
08:46:28 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00243 11m ago Tor Exit Node Connection Medium Investigating SRV-FILE-01
ALR-00460 1h ago Malware Signature Match Low Escalated WS-PC-002
ALR-00329 7h ago Kerberoasting Attempt Low Open SRV-FILE-01
ALR-00118 9h ago Malware Signature Match Medium Resolved FW-EDGE-01
ALR-00398 14h ago Certificate Anomaly Medium Investigating SRV-FILE-01