Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 15:57:58 UTC

Port Scan Detected

Medium False Positive
ALR-00494 · 2026-05-25T03:46:36Z

Description

Sequential port scan (1-1024) detected targeting WS-MAC-005 from external IP. DecoyPulse identified SYN scan pattern.

Alert Metadata

Alert ID
ALR-00494
Timestamp
2026-05-25T03:46:36Z
Severity
Medium
Status
False Positive
Detection Source
DecoyPulse
Assigned Analyst
Anika Patel

Endpoint Information

Hostname
WS-MAC-005
User Account
k.brown
Source IP
91.12.195.119
Destination IP
10.1.161.196
Origin Country
VN Vietnam

MITRE ATT&CK Mapping

Tactic
Reconnaissance
Technique
T1046
Reference
attack.mitre.org/techniques/T1046

Investigation Timeline

03:46:36 Event ingested by SOC365 Engine
03:46:38 EmilyAI triage started — correlation enrichment
03:46:51 EmilyAI confidence: 89% — escalated to human analyst
03:47:00 Alert assigned to analyst: Anika Patel
03:47:33 Investigation started — querying SIEM and threat intelligence
03:53:58 Containment action taken — endpoint isolated
04:02:25 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00163 1h ago Port Scan Detected Low Open VM-DEV-01
ALR-00055 7h ago Port Scan Detected Medium Open WS-PC-003
ALR-00495 7h ago Port Scan Detected Informational False Positive WS-LAP-012
ALR-00249 11h ago Data Exfiltration Attempt Critical Open WS-MAC-005
ALR-00386 12h ago Port Scan Detected Low Resolved WS-PC-002