Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 14:37:21 UTC

All Alerts

ID Timestamp Alert Type Severity Status Source Hostname User Origin Analyst MITRE
ALR-00056 1h ago C2 Beacon Activity Medium Escalated Attack Surface Scanner VM-DEV-01 f.hall VN Vietnam Sarah Chen T1071.001
ALR-00075 1h ago Suspicious PowerShell Execution Informational False Positive Email Gateway WS-PC-001 k.brown US United States EmilyAI (auto) T1059.001
ALR-00033 3h ago DecoyPulse Honeypot Triggered Low Escalated Network IDS WS-PC-001 e.evans RU Russia EmilyAI (auto) T1018
ALR-00079 7h ago Phishing Email Blocked Medium False Positive EmilyAI Triage WS-PC-001 p.thomas KP North Korea Sarah Chen T1566.001
ALR-00040 8h ago Certificate Anomaly Informational Resolved Cloud Connector WS-LAP-012 d.walker GB United Kingdom EmilyAI (auto) T1553.004
ALR-00039 9h ago Suspicious PowerShell Execution Low Resolved DecoyPulse VM-DEV-01 n.clark GB United Kingdom EmilyAI (auto) T1059.001
ALR-00013 10h ago Tor Exit Node Connection Low Resolved Network IDS WS-PC-006 n.clark NL Netherlands EmilyAI (auto) T1090.003
ALR-00060 16h ago Anomalous DNS Query Informational Resolved Attack Surface Scanner WS-PC-002 l.johnson NG Nigeria EmilyAI (auto) T1568.002
ALR-00004 16h ago C2 Beacon Activity Low Resolved Endpoint Agent WS-PC-003 system US United States EmilyAI (auto) T1071.001
ALR-00065 16h ago Insider Threat Indicator Low Investigating Firewall SW-CORE-01 n.clark IR Iran EmilyAI (auto) T1119
ALR-00016 18h ago Brute Force SSH Medium Resolved Network IDS SW-CORE-01 h.roberts CN China James Okonkwo T1110.001
ALR-00006 19h ago Port Scan Detected Medium Open Network IDS FW-EDGE-01 j.smith US United States Marcus Webb T1046
ALR-00084 22h ago Insider Threat Indicator High Escalated DecoyPulse WS-PC-001 n.clark KP North Korea Sarah Chen T1119
ALR-00097 1d ago Certificate Anomaly Low False Positive Email Gateway WS-PC-003 k.brown KP North Korea EmilyAI (auto) T1553.004
ALR-00099 1d ago Malware Signature Match Medium False Positive Attack Surface Scanner SRV-BACKUP-01 s.jones US United States Emma Richardson T1204.002
ALR-00090 1d ago DecoyPulse Honeypot Triggered Low Escalated DLP Module WS-PC-001 k.brown UA Ukraine EmilyAI (auto) T1018
ALR-00057 1d ago Ransomware Behaviour Detected Low Resolved Dark Web Monitor SRV-MAIL-01 k.brown IN India EmilyAI (auto) T1486
ALR-00098 1d ago Kerberoasting Attempt Medium False Positive DecoyPulse SRV-WEB-01 d.walker NG Nigeria Anika Patel T1558.003
ALR-00002 1d ago Tor Exit Node Connection Medium Resolved Network IDS WS-PC-004 r.davies NL Netherlands James Okonkwo T1090.003
ALR-00052 1d ago Tor Exit Node Connection Low False Positive Endpoint Agent SRV-DC-01 s.jones NL Netherlands EmilyAI (auto) T1090.003
ALR-00085 1d ago Phishing Email Blocked Medium Resolved SOC365 Engine WS-LAP-012 e.evans NL Netherlands Anika Patel T1566.001
ALR-00087 1d ago Unusual Outbound Traffic Low Escalated Dark Web Monitor WS-LAP-012 system IN India EmilyAI (auto) T1041
ALR-00011 1d ago Shadow IT Discovery High Investigating DLP Module SRV-MAIL-01 n.clark NL Netherlands Emma Richardson T1567
ALR-00094 1d ago Suspicious PowerShell Execution Informational Investigating Email Gateway WS-PC-003 a.wilson NL Netherlands EmilyAI (auto) T1059.001
ALR-00074 1d ago Certificate Anomaly Medium Resolved SOC365 Engine SRV-FILE-01 j.smith UA Ukraine Sarah Chen T1553.004
ALR-00037 1d ago Malware Signature Match Critical Investigating Cloud Connector SRV-SQL-01 s.jones UA Ukraine Sarah Chen T1204.002
ALR-00035 1d ago Insider Threat Indicator Low Investigating DLP Module SRV-WEB-01 e.evans NG Nigeria EmilyAI (auto) T1119
ALR-00030 1d ago Port Scan Detected Medium Escalated Dark Web Monitor FW-EDGE-01 s.jones BR Brazil Marcus Webb T1046
ALR-00001 1d ago Tor Exit Node Connection Medium False Positive DLP Module WS-PC-003 j.smith NL Netherlands Marcus Webb T1090.003
ALR-00032 1d ago Port Scan Detected Medium Investigating Attack Surface Scanner FW-EDGE-01 l.johnson VN Vietnam James Okonkwo T1046
ALR-00091 1d ago Pass-the-Hash Detected High Escalated Dark Web Monitor WS-PC-002 j.smith GB United Kingdom Anika Patel T1550.002
ALR-00089 1d ago Suspicious PowerShell Execution Low False Positive Firewall SRV-SQL-01 j.smith US United States EmilyAI (auto) T1059.001
ALR-00068 2d ago Port Scan Detected Low Open Cloud Connector SRV-MAIL-01 c.williams IN India EmilyAI (auto) T1046
ALR-00063 2d ago Kerberoasting Attempt Low Escalated Firewall SRV-DC-01 j.smith BR Brazil EmilyAI (auto) T1558.003
ALR-00061 2d ago C2 Beacon Activity Medium Resolved EmilyAI Triage WS-LAP-011 f.hall CN China Marcus Webb T1071.001
ALR-00029 2d ago Insider Threat Indicator Medium Resolved Email Gateway WS-PC-002 a.wilson FR France Emma Richardson T1119
ALR-00023 2d ago Ransomware Behaviour Detected High Investigating Attack Surface Scanner WS-PC-006 system VN Vietnam James Okonkwo T1486
ALR-00036 2d ago Pass-the-Hash Detected Medium False Positive Network IDS FW-EDGE-01 l.johnson BR Brazil Anika Patel T1550.002
ALR-00047 2d ago Lateral Movement Detected Low Open Attack Surface Scanner WS-PC-002 a.wilson UA Ukraine EmilyAI (auto) T1021.002
ALR-00005 2d ago Pass-the-Hash Detected Low False Positive Dark Web Monitor WS-LAP-010 system RO Romania EmilyAI (auto) T1550.002
ALR-00008 2d ago Malware Signature Match Low False Positive Cloud Connector WS-PC-002 f.hall UA Ukraine EmilyAI (auto) T1204.002
ALR-00025 2d ago Insider Threat Indicator Low Resolved Endpoint Agent WS-MAC-005 e.evans RO Romania EmilyAI (auto) T1119
ALR-00026 2d ago DecoyPulse Honeypot Triggered Medium Investigating Cloud Connector SRV-WEB-01 p.thomas DE Germany Anika Patel T1018
ALR-00077 2d ago Failed MFA Challenge Medium Escalated Email Gateway WS-LAP-010 k.brown US United States Emma Richardson T1621
ALR-00042 3d ago Privilege Escalation Attempt Medium Investigating SOC365 Engine SRV-MAIL-01 system RO Romania Emma Richardson T1134
ALR-00100 3d ago Anomalous DNS Query Low Open SOC365 Engine WS-PC-006 system RO Romania EmilyAI (auto) T1568.002
ALR-00012 3d ago Phishing Email Blocked Low False Positive Dark Web Monitor SW-CORE-01 d.walker RU Russia EmilyAI (auto) T1566.001
ALR-00076 3d ago C2 Beacon Activity Informational False Positive DLP Module WS-PC-001 n.clark IR Iran EmilyAI (auto) T1071.001
ALR-00049 3d ago Insider Threat Indicator Low Open DecoyPulse WS-PC-003 e.evans UA Ukraine EmilyAI (auto) T1119
ALR-00069 3d ago Anomalous DNS Query High Investigating Email Gateway WS-PC-004 j.smith FR France Anika Patel T1568.002
ALR-00066 3d ago Phishing Email Blocked Medium Investigating Dark Web Monitor WS-LAP-010 m.taylor RO Romania Emma Richardson T1566.001
ALR-00053 3d ago Shadow IT Discovery Medium Investigating Attack Surface Scanner WS-LAP-010 s.jones NG Nigeria James Okonkwo T1567
ALR-00031 3d ago Ransomware Behaviour Detected Informational Investigating Email Gateway WS-LAP-011 p.thomas CN China EmilyAI (auto) T1486
ALR-00096 3d ago Failed MFA Challenge Medium False Positive Dark Web Monitor WS-LAP-012 system FR France James Okonkwo T1621
ALR-00009 3d ago Rogue DHCP Server Low False Positive Dark Web Monitor WS-MAC-005 j.smith IN India EmilyAI (auto) T1557.003
ALR-00086 3d ago Malware Signature Match Informational Escalated Endpoint Agent SRV-MAIL-01 f.hall CN China EmilyAI (auto) T1204.002
ALR-00081 3d ago Suspicious PowerShell Execution Informational Resolved EmilyAI Triage VM-DEV-01 n.clark IN India EmilyAI (auto) T1059.001
ALR-00054 3d ago Kerberoasting Attempt Medium Resolved Attack Surface Scanner SW-CORE-01 m.taylor RU Russia Anika Patel T1558.003
ALR-00093 4d ago Suspicious PowerShell Execution Informational Resolved Dark Web Monitor SW-CORE-01 system UA Ukraine EmilyAI (auto) T1059.001
ALR-00071 4d ago Port Scan Detected Low False Positive Firewall WS-PC-006 k.brown UA Ukraine EmilyAI (auto) T1046
ALR-00014 4d ago Kerberoasting Attempt Informational Investigating Cloud Connector WS-PC-006 p.thomas DE Germany EmilyAI (auto) T1558.003
ALR-00044 4d ago Pass-the-Hash Detected Informational Investigating Endpoint Agent WS-PC-004 system NG Nigeria EmilyAI (auto) T1550.002
ALR-00046 4d ago Ransomware Behaviour Detected Informational Investigating DLP Module WS-MAC-005 a.wilson KP North Korea EmilyAI (auto) T1486
ALR-00088 4d ago DLP Policy Violation Medium Resolved Endpoint Agent WS-PC-001 system VN Vietnam Marcus Webb T1048
ALR-00038 4d ago Shadow IT Discovery Medium Investigating EmilyAI Triage SRV-BACKUP-01 e.evans RO Romania Sarah Chen T1567
ALR-00058 4d ago Unauthorised USB Device Medium Investigating EmilyAI Triage WS-LAP-011 a.wilson FR France Marcus Webb T1091
ALR-00003 4d ago Unauthorised USB Device Low Resolved Network IDS WS-LAP-010 f.hall RO Romania EmilyAI (auto) T1091
ALR-00073 4d ago Pass-the-Hash Detected Low Investigating Firewall WS-MAC-005 e.evans KP North Korea EmilyAI (auto) T1550.002
ALR-00021 4d ago Insider Threat Indicator Informational False Positive EmilyAI Triage WS-PC-002 k.brown FR France EmilyAI (auto) T1119
ALR-00019 4d ago Failed MFA Challenge Medium Investigating Endpoint Agent WS-PC-004 l.johnson GB United Kingdom James Okonkwo T1621
ALR-00043 5d ago Unauthorised USB Device Low Escalated SOC365 Engine AP-WIFI-03 m.taylor IN India EmilyAI (auto) T1091
ALR-00020 5d ago Unauthorised USB Device Informational Open Attack Surface Scanner WS-PC-006 r.davies BR Brazil EmilyAI (auto) T1091
ALR-00027 5d ago Privilege Escalation Attempt Informational False Positive DLP Module AP-WIFI-03 system VN Vietnam EmilyAI (auto) T1134
ALR-00007 5d ago DecoyPulse Honeypot Triggered Low Resolved DecoyPulse SRV-SQL-01 r.davies UA Ukraine EmilyAI (auto) T1018
ALR-00048 5d ago Pass-the-Hash Detected Low Open Network IDS WS-LAP-011 p.thomas GB United Kingdom EmilyAI (auto) T1550.002
ALR-00082 5d ago Credential Stuffing Attempt Informational Resolved EmilyAI Triage SRV-MAIL-01 e.evans US United States EmilyAI (auto) T1110.004
ALR-00055 5d ago Data Exfiltration Attempt Low Open EmilyAI Triage SRV-SQL-01 r.davies RO Romania EmilyAI (auto) T1567.002
ALR-00072 5d ago Unusual Outbound Traffic High Open SOC365 Engine WS-PC-006 l.johnson IR Iran Emma Richardson T1041
ALR-00083 5d ago Brute Force SSH Medium Escalated Attack Surface Scanner SRV-SQL-01 e.evans CN China Anika Patel T1110.001
ALR-00064 5d ago Brute Force SSH Medium Escalated Attack Surface Scanner SRV-SQL-01 c.williams NL Netherlands Marcus Webb T1110.001
ALR-00018 5d ago Certificate Anomaly High Investigating Endpoint Agent SRV-WEB-01 e.evans IN India James Okonkwo T1553.004
ALR-00017 5d ago C2 Beacon Activity High Open DecoyPulse WS-PC-002 j.smith IR Iran Emma Richardson T1071.001
ALR-00024 5d ago Rogue DHCP Server Low False Positive Email Gateway SRV-FILE-01 j.smith GB United Kingdom EmilyAI (auto) T1557.003
ALR-00092 5d ago C2 Beacon Activity Medium Resolved EmilyAI Triage SRV-DC-01 f.hall BR Brazil Sarah Chen T1071.001
ALR-00045 5d ago DLP Policy Violation Medium Investigating Attack Surface Scanner WS-LAP-010 s.jones FR France Sarah Chen T1048
ALR-00080 5d ago Certificate Anomaly Low Open Email Gateway SRV-BACKUP-01 a.wilson DE Germany EmilyAI (auto) T1553.004
ALR-00051 5d ago Malware Signature Match Low Escalated Email Gateway WS-PC-001 p.thomas US United States EmilyAI (auto) T1204.002
ALR-00028 5d ago Shadow IT Discovery Informational False Positive Network IDS WS-LAP-010 p.thomas US United States EmilyAI (auto) T1567
ALR-00010 5d ago Brute Force SSH Informational Open Firewall SRV-DC-01 j.smith DE Germany EmilyAI (auto) T1110.001
ALR-00015 5d ago Kerberoasting Attempt Low Resolved DecoyPulse SRV-DC-01 p.thomas RO Romania EmilyAI (auto) T1558.003
ALR-00022 5d ago Anomalous DNS Query Informational Resolved Network IDS VM-DEV-01 n.clark DE Germany EmilyAI (auto) T1568.002
ALR-00062 6d ago Anomalous DNS Query Low Resolved DLP Module SRV-SQL-01 a.wilson KP North Korea EmilyAI (auto) T1568.002
ALR-00078 6d ago Brute Force SSH Informational Open Email Gateway WS-PC-001 p.thomas UA Ukraine EmilyAI (auto) T1110.001
ALR-00059 6d ago Rogue DHCP Server High Open Cloud Connector WS-PC-004 e.evans IR Iran Sarah Chen T1557.003
ALR-00095 6d ago Insider Threat Indicator Low False Positive DecoyPulse SRV-WEB-01 j.smith US United States EmilyAI (auto) T1119
ALR-00034 6d ago Suspicious Scheduled Task Informational Resolved Cloud Connector FW-EDGE-01 d.walker RO Romania EmilyAI (auto) T1053.005
ALR-00067 6d ago Suspicious PowerShell Execution Medium Investigating Dark Web Monitor AP-WIFI-03 r.davies NG Nigeria Marcus Webb T1059.001
ALR-00041 6d ago Malware Signature Match Informational Escalated SOC365 Engine SRV-APP-01 f.hall RU Russia EmilyAI (auto) T1204.002
ALR-00050 6d ago DecoyPulse Honeypot Triggered Informational Resolved Cloud Connector SRV-SQL-01 n.clark NL Netherlands EmilyAI (auto) T1018
ALR-00070 6d ago C2 Beacon Activity Low Resolved DLP Module SW-CORE-01 p.thomas FR France EmilyAI (auto) T1071.001