The following is an automated response sent to you by the QRadar offense custom rules engine. Offense CRE Rule #114875, "Qradar Offense Alert" fired Rule Notes: -------------------------------------------------- Offense #30380 Start Time: Sun Nov 19 19:55:43 CST 2017 https://10.1.255.81/console/qradar/jsp/QRadar.jsp?appName=Sem&pageId=OffenseSummary&summaryId=30380 Magnitude: 4, Relevance 2, Severity: 8, Credibility 2 Description: IRC Connections preceded by Local IRC Server Detected containing Built TCP connection Event count for this offense: 4 Flow count for this offense: 0 in 3 categories Offense Source Summary: Source: 162.213.33.196 Location: United States User: N/A Mac: N/A Destination IP: 10.206.96.16 Host: N/A Asset Name: N/A Offenses: 4 Events/Flows: 18