Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 15:20:18 UTC

Tor Exit Node Connection

Medium False Positive
ALR-00488 · 2026-04-06T16:31:54Z

Description

Connection from WS-LAP-012 to known Tor exit node detected by DLP Module. User 'k.brown' was active at the time.

Alert Metadata

Alert ID
ALR-00488
Timestamp
2026-04-06T16:31:54Z
Severity
Medium
Status
False Positive
Detection Source
DLP Module
Assigned Analyst
Emma Richardson

Endpoint Information

Hostname
WS-LAP-012
User Account
k.brown
Source IP
194.109.62.139
Destination IP
10.1.216.69
Origin Country
KP North Korea

MITRE ATT&CK Mapping

Tactic
Command and Control
Technique
T1090.003
Reference
attack.mitre.org/techniques/T1090.003

Investigation Timeline

16:31:54 Event ingested by SOC365 Engine
16:31:57 EmilyAI triage started — correlation enrichment
16:32:04 EmilyAI confidence: 93% — escalated to human analyst
16:32:11 Alert assigned to analyst: Emma Richardson
16:34:44 Investigation started — querying SIEM and threat intelligence
16:39:59 Containment action taken — endpoint isolated
16:50:57 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00368 3h ago Shadow IT Discovery Low Resolved WS-LAP-012
ALR-00023 4h ago Pass-the-Hash Detected Low Escalated WS-LAP-012
ALR-00013 10h ago Tor Exit Node Connection Low Escalated WS-PC-003
ALR-00344 10h ago Malware Signature Match Low Resolved WS-LAP-012
ALR-00383 11h ago Privilege Escalation Attempt High Escalated WS-LAP-012