Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 17:08:20 UTC

C2 Beacon Activity

Low Resolved
ALR-00495 · 2026-05-27T13:19:56Z

Description

Suspected C2 beacon detected from WS-PC-002. Regular 60-second interval HTTPS POST to suspicious domain. Cloud Connector blocked outbound.

Alert Metadata

Alert ID
ALR-00495
Timestamp
2026-05-27T13:19:56Z
Severity
Low
Status
Resolved
Detection Source
Cloud Connector
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
WS-PC-002
User Account
a.wilson
Source IP
91.174.195.221
Destination IP
10.0.253.103
Origin Country
NL Netherlands

MITRE ATT&CK Mapping

Tactic
Command and Control
Technique
T1071.001
Reference
attack.mitre.org/techniques/T1071.001

Investigation Timeline

13:19:56 Event ingested by SOC365 Engine
13:19:58 EmilyAI triage started — correlation enrichment
13:20:08 EmilyAI confidence: 95% — escalated to human analyst
13:20:14 Alert assigned to analyst: EmilyAI (auto)
13:21:07 Investigation started — querying SIEM and threat intelligence
13:28:48 Containment action taken — endpoint isolated
13:38:22 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00300 40m ago Suspicious Scheduled Task High Investigating WS-PC-002
ALR-00407 11h ago C2 Beacon Activity Medium Escalated SRV-WEB-01
ALR-00111 12h ago C2 Beacon Activity Medium Escalated WS-MAC-005
ALR-00169 14h ago C2 Beacon Activity Low Resolved FW-EDGE-01
ALR-00385 21h ago Anomalous DNS Query High Investigating WS-PC-002