Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 16:57:30 UTC

Rogue DHCP Server

Informational Resolved
ALR-00468 · 2026-04-11T12:07:34Z

Description

Rogue DHCP server detected on VLAN 10 from WS-PC-006. Offering IPs in unexpected range. Email Gateway quarantined the device.

Alert Metadata

Alert ID
ALR-00468
Timestamp
2026-04-11T12:07:34Z
Severity
Informational
Status
Resolved
Detection Source
Email Gateway
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
WS-PC-006
User Account
s.jones
Source IP
91.60.195.52
Destination IP
10.1.199.95
Origin Country
VN Vietnam

MITRE ATT&CK Mapping

Tactic
Discovery
Technique
T1557.003
Reference
attack.mitre.org/techniques/T1557.003

Investigation Timeline

12:07:34 Event ingested by SOC365 Engine
12:07:39 EmilyAI triage started — correlation enrichment
12:07:45 EmilyAI confidence: 84% — escalated to human analyst
12:08:14 Alert assigned to analyst: EmilyAI (auto)
12:09:05 Investigation started — querying SIEM and threat intelligence
12:11:42 Containment action taken — endpoint isolated
12:18:29 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00316 1h ago Shadow IT Discovery Low Escalated WS-PC-006
ALR-00146 4h ago Rogue DHCP Server Medium False Positive SRV-DC-01
ALR-00286 5h ago Lateral Movement Detected Medium Open WS-PC-006
ALR-00055 6h ago Malware Signature Match Informational Open WS-PC-006
ALR-00337 8h ago Rogue DHCP Server Low Resolved WS-PC-002