Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 15:26:20 UTC

Tor Exit Node Connection

Informational Open
ALR-00479 · 2026-04-10T07:54:19Z

Description

Connection from WS-LAP-011 to known Tor exit node detected by Dark Web Monitor. User 'n.clark' was active at the time.

Alert Metadata

Alert ID
ALR-00479
Timestamp
2026-04-10T07:54:19Z
Severity
Informational
Status
Open
Detection Source
Dark Web Monitor
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
WS-LAP-011
User Account
n.clark
Source IP
91.67.195.134
Destination IP
10.2.69.176
Origin Country
IN India

MITRE ATT&CK Mapping

Tactic
Command and Control
Technique
T1090.003
Reference
attack.mitre.org/techniques/T1090.003

Investigation Timeline

07:54:19 Event ingested by SOC365 Engine
07:54:20 EmilyAI triage started — correlation enrichment
07:54:28 EmilyAI confidence: 81% — escalated to human analyst
07:54:36 Alert assigned to analyst: EmilyAI (auto)
07:55:38 Investigation started — querying SIEM and threat intelligence

Related Alerts

ID Time Alert Severity Status Host
ALR-00461 30m ago Tor Exit Node Connection Low Open WS-PC-006
ALR-00227 1h ago Tor Exit Node Connection Critical Escalated WS-LAP-011
ALR-00440 4h ago DecoyPulse Honeypot Triggered Medium Investigating WS-LAP-011
ALR-00209 14h ago Tor Exit Node Connection Low Escalated FW-EDGE-01
ALR-00115 20h ago Credential Stuffing Attempt Informational Open WS-LAP-011