Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 15:51:35 UTC

Medium Alerts

Clear
ID Timestamp Alert Type Severity Status Source Hostname User Origin Analyst MITRE
ALR-00208 11m ago Pass-the-Hash Detected Medium Open Network IDS WS-PC-004 r.davies NL Netherlands Sarah Chen T1550.002
ALR-00267 43m ago Certificate Anomaly Medium Escalated Attack Surface Scanner VM-DEV-01 r.davies VN Vietnam Marcus Webb T1553.004
ALR-00112 2h ago Kerberoasting Attempt Medium Investigating Attack Surface Scanner WS-LAP-010 a.wilson IN India Marcus Webb T1558.003
ALR-00158 4h ago Ransomware Behaviour Detected Medium Investigating Network IDS AP-WIFI-03 h.roberts VN Vietnam Anika Patel T1486
ALR-00012 5h ago C2 Beacon Activity Medium Open Cloud Connector WS-PC-006 n.clark GB United Kingdom Anika Patel T1071.001
ALR-00176 7h ago Data Exfiltration Attempt Medium Open Network IDS SRV-SQL-01 e.evans NG Nigeria James Okonkwo T1567.002
ALR-00118 8h ago Malware Signature Match Medium Open Email Gateway SRV-APP-01 m.taylor KP North Korea Marcus Webb T1204.002
ALR-00219 11h ago Ransomware Behaviour Detected Medium Escalated Attack Surface Scanner WS-LAP-012 s.jones VN Vietnam Emma Richardson T1486
ALR-00258 14h ago Insider Threat Indicator Medium False Positive Endpoint Agent SRV-FILE-01 f.hall US United States Sarah Chen T1119
ALR-00182 18h ago Pass-the-Hash Detected Medium Resolved SOC365 Engine WS-PC-006 e.evans NG Nigeria Emma Richardson T1550.002
ALR-00086 1d ago Certificate Anomaly Medium Escalated SOC365 Engine WS-PC-006 d.walker KP North Korea Anika Patel T1553.004
ALR-00056 1d ago Phishing Email Blocked Medium Escalated Dark Web Monitor SRV-FILE-01 k.brown UA Ukraine James Okonkwo T1566.001
ALR-00194 1d ago Port Scan Detected Medium Escalated Endpoint Agent WS-LAP-010 k.brown VN Vietnam Anika Patel T1046
ALR-00235 1d ago Certificate Anomaly Medium Open Network IDS SRV-DC-01 h.roberts CN China Anika Patel T1553.004
ALR-00272 1d ago Insider Threat Indicator Medium Escalated Firewall SRV-WEB-01 e.evans IR Iran Sarah Chen T1119
ALR-00172 1d ago Credential Stuffing Attempt Medium Open SOC365 Engine WS-PC-001 l.johnson CN China Marcus Webb T1110.004
ALR-00275 1d ago Lateral Movement Detected Medium Escalated Network IDS SRV-BACKUP-01 s.jones CN China Anika Patel T1021.002
ALR-00080 1d ago DLP Policy Violation Medium Escalated DLP Module WS-PC-002 k.brown US United States Emma Richardson T1048
ALR-00156 1d ago Data Exfiltration Attempt Medium False Positive Endpoint Agent SRV-BACKUP-01 c.williams UA Ukraine James Okonkwo T1567.002
ALR-00098 1d ago Lateral Movement Detected Medium Resolved DLP Module WS-PC-006 d.walker BR Brazil James Okonkwo T1021.002
ALR-00246 1d ago Certificate Anomaly Medium Escalated DecoyPulse FW-EDGE-01 k.brown UA Ukraine Emma Richardson T1553.004
ALR-00064 1d ago Malware Signature Match Medium False Positive Email Gateway SW-CORE-01 n.clark VN Vietnam Sarah Chen T1204.002
ALR-00201 1d ago Anomalous DNS Query Medium Escalated DLP Module SRV-FILE-01 p.thomas CN China James Okonkwo T1568.002
ALR-00240 1d ago Pass-the-Hash Detected Medium Open Dark Web Monitor SRV-FILE-01 p.thomas RU Russia Marcus Webb T1550.002
ALR-00239 1d ago DecoyPulse Honeypot Triggered Medium Escalated Cloud Connector VM-DEV-01 m.taylor GB United Kingdom Emma Richardson T1018
ALR-00087 1d ago Lateral Movement Detected Medium Open Network IDS WS-LAP-010 s.jones US United States Anika Patel T1021.002
ALR-00054 1d ago DLP Policy Violation Medium Escalated Network IDS SRV-DC-01 h.roberts NG Nigeria James Okonkwo T1048
ALR-00192 2d ago C2 Beacon Activity Medium Resolved Cloud Connector SRV-BACKUP-01 c.williams GB United Kingdom Marcus Webb T1071.001
ALR-00210 2d ago C2 Beacon Activity Medium Escalated Network IDS SW-CORE-01 l.johnson US United States Emma Richardson T1071.001
ALR-00019 2d ago Certificate Anomaly Medium Escalated Endpoint Agent SRV-APP-01 r.davies IN India Marcus Webb T1553.004
ALR-00171 2d ago DecoyPulse Honeypot Triggered Medium Resolved Email Gateway SRV-FILE-01 system DE Germany Anika Patel T1018
ALR-00211 2d ago Rogue DHCP Server Medium Resolved SOC365 Engine SRV-SQL-01 n.clark RU Russia Marcus Webb T1557.003
ALR-00174 2d ago Phishing Email Blocked Medium Open Dark Web Monitor SRV-DC-01 system RU Russia Sarah Chen T1566.001
ALR-00143 2d ago Rogue DHCP Server Medium Escalated Network IDS SRV-FILE-01 j.smith RU Russia Anika Patel T1557.003
ALR-00053 2d ago Credential Stuffing Attempt Medium Escalated Dark Web Monitor SRV-FILE-01 f.hall NL Netherlands Anika Patel T1110.004
ALR-00046 2d ago Lateral Movement Detected Medium Investigating Network IDS SRV-SQL-01 h.roberts US United States James Okonkwo T1021.002
ALR-00026 2d ago Suspicious PowerShell Execution Medium Resolved DLP Module WS-LAP-010 k.brown FR France Sarah Chen T1059.001
ALR-00282 2d ago Data Exfiltration Attempt Medium Open Network IDS WS-PC-002 c.williams CN China Marcus Webb T1567.002
ALR-00212 2d ago Pass-the-Hash Detected Medium Open DLP Module WS-LAP-012 system UA Ukraine Anika Patel T1550.002
ALR-00268 2d ago Phishing Email Blocked Medium Open Dark Web Monitor FW-EDGE-01 n.clark NL Netherlands James Okonkwo T1566.001
ALR-00187 2d ago Brute Force SSH Medium Open Firewall AP-WIFI-03 c.williams VN Vietnam Emma Richardson T1110.001
ALR-00018 2d ago Malware Signature Match Medium Investigating SOC365 Engine SRV-SQL-01 n.clark UA Ukraine Marcus Webb T1204.002
ALR-00249 2d ago Failed MFA Challenge Medium Open Cloud Connector WS-PC-001 k.brown UA Ukraine Anika Patel T1621
ALR-00072 2d ago Port Scan Detected Medium Investigating Network IDS WS-PC-003 h.roberts FR France Sarah Chen T1046
ALR-00005 3d ago Shadow IT Discovery Medium Open Email Gateway SRV-BACKUP-01 r.davies GB United Kingdom Anika Patel T1567
ALR-00038 3d ago Unauthorised USB Device Medium Investigating EmilyAI Triage SRV-BACKUP-01 r.davies FR France James Okonkwo T1091
ALR-00111 3d ago Brute Force SSH Medium Open Dark Web Monitor WS-PC-004 p.thomas KP North Korea Marcus Webb T1110.001
ALR-00015 3d ago Failed MFA Challenge Medium Open EmilyAI Triage SRV-BACKUP-01 f.hall VN Vietnam Emma Richardson T1621
ALR-00241 3d ago Ransomware Behaviour Detected Medium Investigating Email Gateway SRV-MAIL-01 e.evans UA Ukraine James Okonkwo T1486
ALR-00108 3d ago Kerberoasting Attempt Medium Resolved Email Gateway WS-LAP-011 s.jones RO Romania Emma Richardson T1558.003
ALR-00039 3d ago Credential Stuffing Attempt Medium Investigating Attack Surface Scanner FW-EDGE-01 n.clark NG Nigeria Anika Patel T1110.004
ALR-00216 3d ago Certificate Anomaly Medium Resolved EmilyAI Triage FW-EDGE-01 s.jones FR France James Okonkwo T1553.004
ALR-00229 3d ago DecoyPulse Honeypot Triggered Medium Escalated Cloud Connector WS-MAC-005 m.taylor RO Romania Anika Patel T1018
ALR-00304 3d ago Insider Threat Indicator Medium Investigating SOC365 Engine WS-PC-006 e.evans IN India Anika Patel T1119
ALR-00024 3d ago Failed MFA Challenge Medium False Positive Email Gateway WS-PC-003 s.jones CN China Marcus Webb T1621
ALR-00059 3d ago C2 Beacon Activity Medium False Positive EmilyAI Triage SRV-MAIL-01 n.clark BR Brazil James Okonkwo T1071.001
ALR-00133 3d ago Unauthorised USB Device Medium Resolved DecoyPulse WS-LAP-010 f.hall UA Ukraine Sarah Chen T1091
ALR-00055 3d ago Failed MFA Challenge Medium Escalated Attack Surface Scanner SRV-SQL-01 d.walker RU Russia James Okonkwo T1621
ALR-00214 3d ago Anomalous DNS Query Medium Open Endpoint Agent AP-WIFI-03 k.brown IN India James Okonkwo T1568.002
ALR-00050 3d ago Anomalous DNS Query Medium Resolved Attack Surface Scanner WS-LAP-010 p.thomas RO Romania James Okonkwo T1568.002
ALR-00271 4d ago Tor Exit Node Connection Medium Investigating DLP Module FW-EDGE-01 n.clark NG Nigeria Sarah Chen T1090.003
ALR-00286 4d ago Pass-the-Hash Detected Medium Open Endpoint Agent SRV-WEB-01 c.williams NG Nigeria Sarah Chen T1550.002
ALR-00043 4d ago DLP Policy Violation Medium False Positive Dark Web Monitor WS-PC-002 l.johnson US United States Anika Patel T1048
ALR-00170 4d ago Rogue DHCP Server Medium Resolved Dark Web Monitor SRV-BACKUP-01 system UA Ukraine Marcus Webb T1557.003
ALR-00270 4d ago Anomalous DNS Query Medium Investigating SOC365 Engine SRV-APP-01 f.hall FR France Marcus Webb T1568.002
ALR-00162 4d ago Rogue DHCP Server Medium Resolved Dark Web Monitor SRV-SQL-01 h.roberts KP North Korea Anika Patel T1557.003
ALR-00122 4d ago Unusual Outbound Traffic Medium Open Attack Surface Scanner WS-LAP-011 m.taylor IN India Anika Patel T1041
ALR-00119 4d ago Suspicious Scheduled Task Medium Open DecoyPulse WS-LAP-011 l.johnson NG Nigeria Anika Patel T1053.005
ALR-00082 4d ago Certificate Anomaly Medium Resolved Firewall VM-DEV-01 h.roberts RU Russia Marcus Webb T1553.004
ALR-00009 4d ago Ransomware Behaviour Detected Medium Open Firewall SRV-APP-01 a.wilson GB United Kingdom Sarah Chen T1486
ALR-00104 4d ago Unusual Outbound Traffic Medium Open Endpoint Agent WS-MAC-005 m.taylor DE Germany Sarah Chen T1041
ALR-00141 4d ago Privilege Escalation Attempt Medium Open EmilyAI Triage WS-PC-002 h.roberts VN Vietnam Anika Patel T1134
ALR-00033 4d ago Kerberoasting Attempt Medium Escalated EmilyAI Triage SRV-WEB-01 k.brown IR Iran Anika Patel T1558.003
ALR-00075 4d ago Lateral Movement Detected Medium Open Cloud Connector FW-EDGE-01 c.williams CN China Emma Richardson T1021.002
ALR-00217 4d ago Privilege Escalation Attempt Medium False Positive Cloud Connector WS-PC-006 e.evans RU Russia Sarah Chen T1134
ALR-00296 5d ago Unauthorised USB Device Medium Open EmilyAI Triage SW-CORE-01 h.roberts KP North Korea Marcus Webb T1091
ALR-00288 5d ago Data Exfiltration Attempt Medium False Positive Endpoint Agent WS-LAP-010 j.smith KP North Korea James Okonkwo T1567.002
ALR-00237 5d ago Anomalous DNS Query Medium Investigating Endpoint Agent FW-EDGE-01 n.clark IN India Sarah Chen T1568.002
ALR-00151 5d ago Unauthorised USB Device Medium Escalated Cloud Connector FW-EDGE-01 e.evans VN Vietnam James Okonkwo T1091
ALR-00004 5d ago Brute Force SSH Medium False Positive DLP Module WS-PC-001 system US United States Sarah Chen T1110.001
ALR-00081 5d ago Unusual Outbound Traffic Medium Investigating DLP Module VM-DEV-01 f.hall UA Ukraine Anika Patel T1041
ALR-00197 5d ago DLP Policy Violation Medium Resolved EmilyAI Triage WS-MAC-005 f.hall CN China Sarah Chen T1048
ALR-00041 5d ago Port Scan Detected Medium False Positive SOC365 Engine FW-EDGE-01 r.davies RO Romania James Okonkwo T1046
ALR-00209 5d ago Pass-the-Hash Detected Medium Investigating Dark Web Monitor WS-PC-006 d.walker IR Iran Marcus Webb T1550.002
ALR-00250 5d ago Credential Stuffing Attempt Medium False Positive Cloud Connector WS-LAP-011 k.brown UA Ukraine Emma Richardson T1110.004
ALR-00179 5d ago Privilege Escalation Attempt Medium Escalated DLP Module WS-PC-002 r.davies UA Ukraine Marcus Webb T1134
ALR-00088 5d ago Unauthorised USB Device Medium Investigating Cloud Connector SRV-MAIL-01 c.williams GB United Kingdom Emma Richardson T1091
ALR-00131 6d ago Shadow IT Discovery Medium Escalated EmilyAI Triage WS-LAP-011 r.davies RO Romania Anika Patel T1567
ALR-00204 6d ago Anomalous DNS Query Medium Investigating Endpoint Agent AP-WIFI-03 d.walker VN Vietnam Sarah Chen T1568.002
ALR-00051 6d ago Failed MFA Challenge Medium Resolved Cloud Connector SRV-SQL-01 system GB United Kingdom James Okonkwo T1621
ALR-00107 6d ago Ransomware Behaviour Detected Medium False Positive SOC365 Engine WS-PC-006 e.evans DE Germany Sarah Chen T1486
ALR-00142 6d ago Rogue DHCP Server Medium Investigating Firewall VM-DEV-01 r.davies IR Iran Sarah Chen T1557.003
ALR-00207 6d ago Insider Threat Indicator Medium False Positive DecoyPulse SRV-BACKUP-01 m.taylor RO Romania Marcus Webb T1119
ALR-00253 6d ago Unauthorised USB Device Medium Escalated Dark Web Monitor SRV-FILE-01 system FR France Marcus Webb T1091
ALR-00257 6d ago Credential Stuffing Attempt Medium Escalated EmilyAI Triage AP-WIFI-03 h.roberts GB United Kingdom James Okonkwo T1110.004
ALR-00149 6d ago Ransomware Behaviour Detected Medium Open Attack Surface Scanner WS-LAP-010 k.brown CN China Anika Patel T1486
ALR-00052 6d ago Rogue DHCP Server Medium False Positive EmilyAI Triage VM-DEV-01 r.davies NG Nigeria Anika Patel T1557.003
ALR-00034 6d ago Credential Stuffing Attempt Medium False Positive SOC365 Engine WS-LAP-011 j.smith NL Netherlands Emma Richardson T1110.004
ALR-00127 6d ago Suspicious PowerShell Execution Medium Resolved Firewall WS-LAP-010 h.roberts US United States Marcus Webb T1059.001
ALR-00181 6d ago C2 Beacon Activity Medium Investigating Dark Web Monitor AP-WIFI-03 e.evans FR France James Okonkwo T1071.001